Commit 00006663 by Yara Rules

Tags

Added new tags
parent 427a2b31
...@@ -2,7 +2,8 @@ ...@@ -2,7 +2,8 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule Adwind_JAR_PACKA { rule Adwind_JAR_PACKA : binary
{
meta: meta:
author = "Vitaly Kamluk, Vitaly.Kamluk@kaspersky.com" author = "Vitaly Kamluk, Vitaly.Kamluk@kaspersky.com"
reference = "https://securelist.com/securelist/files/2016/02/KL_AdwindPublicReport_2016.pdf" reference = "https://securelist.com/securelist/files/2016/02/KL_AdwindPublicReport_2016.pdf"
......
...@@ -2,7 +2,7 @@ ...@@ -2,7 +2,7 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule Adzok rule Adzok : binary
{ {
meta: meta:
author = " Kevin Breen <kevin@techanarchy.net>" author = " Kevin Breen <kevin@techanarchy.net>"
...@@ -18,7 +18,7 @@ rule Adzok ...@@ -18,7 +18,7 @@ rule Adzok
$a2 = "key.classPK" $a2 = "key.classPK"
$a3 = "svd$1.classPK" $a3 = "svd$1.classPK"
$a4 = "svd$2.classPK" $a4 = "svd$2.classPK"
$a5 = "Mensaje.classPK" $a5 = "Mensaje.classPK"
$a6 = "inic$ShutdownHook.class" $a6 = "inic$ShutdownHook.class"
$a7 = "Uninstall.jarPK" $a7 = "Uninstall.jarPK"
$a8 = "resources/icono.pngPK" $a8 = "resources/icono.pngPK"
......
...@@ -2,7 +2,8 @@ ...@@ -2,7 +2,8 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as
long as you use it under this license. long as you use it under this license.
*/ */
rule alina { rule alina : forensics,pcap
{
meta: meta:
author = "Brian Wallace @botnet_hunter" author = "Brian Wallace @botnet_hunter"
author_email = "bwall@ballastsecurity.net" author_email = "bwall@ballastsecurity.net"
......
...@@ -2,7 +2,7 @@ ...@@ -2,7 +2,7 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as
long as you use it under this license. long as you use it under this license.
*/ */
rule andromeda rule andromeda : binary
{ {
meta: meta:
author = "Brian Wallace @botnet_hunter" author = "Brian Wallace @botnet_hunter"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment