Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
0beb16df
Commit
0beb16df
authored
Mar 01, 2016
by
mmorenog
Browse files
Options
Browse Files
Download
Plain Diff
Merge pull request #95 from adamziaja/patch-2
Create Hsdfihdf.yar
parents
9fdc8192
739d9a99
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
39 additions
and
0 deletions
+39
-0
Hsdfihdf.yar
malware/Hsdfihdf.yar
+39
-0
No files found.
malware/Hsdfihdf.yar
0 → 100644
View file @
0beb16df
rule Hsdfihdf
{
meta:
author = "Adam Ziaja <adam@adamziaja.com> http://adamziaja.com"
date = "2014-04-06"
description = "Polish banking malware"
hash0 = "db1675c74a444fd35383d9a45631cada"
hash1 = "f48ba39df38056449a3e9a1a7289f657"
filetype = "exe"
strings:
$s0 = "ANSI_CHARSET"
$s1 = "][Vee_d_["
$s2 = "qfcD:6<"
$s3 = "%-%/%1%3%5%7%9%;%"
$s4 = "imhzxsc\\WWKD<.)w"
$s5 = "Vzlarf\\]VOZVMskf"
$s6 = "JKWFAp\\Z"
$s7 = "<aLLwhg"
$s8 = "bdLeftToRight"
$s9 = "F/.pTC7"
$s10 = "O><8,)-$ "
$s11 = "mjeUB>D.'8)5\\\\vhe["
$s12 = "JGiVRk[W]PL("
$s13 = "zwWNNG:8"
$s14 = "zv7,'$"
$a0 = "#hsdfihdf"
$a1 = "polska.irc.pl"
$b0 = "firehim@o2.pl"
$b1 = "firehim@go2.pl"
$b2 = "firehim@tlen.pl"
$c0 = "cyberpunks.pl"
$c1 = "kaper.phrack.pl"
$c2 = "serwer.uk.to"
$c3 = "ns1.ipv4.hu"
$c4 = "scorebot.koth.hu"
$c5 = "esopoland.pl"
condition:
14 of ($s*) or all of ($a*) or 1 of ($b*) or 2 of ($c*)
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment