Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
1bbd2455
Commit
1bbd2455
authored
Jun 06, 2016
by
Antonio S
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Ruleset for Android Marcher malware
parent
ce86162d
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
61 additions
and
0 deletions
+61
-0
Android_Marcher_2.yar
Mobile_Malware/Android_Marcher_2.yar
+61
-0
No files found.
Mobile_Malware/Android_Marcher_2.yar
0 → 100644
View file @
1bbd2455
rule marcher
{
meta:
author = "Antonio S. <asanchez@koodous.com>"
source = "https://analyst.koodous.com/rulesets/890"
description = "This rule detects is to detect a type of banking malware"
sample = "33b1a9e4a1591c1a39fdd5295874e365dbde9448098254a938525385498da070"
strings:
$a = "cmVudCYmJg=="
$b = "dXNzZCYmJg=="
condition:
all of them
}
rule marcher2
{
meta:
author = "Antonio S. <asanchez@koodous.com>"
source = "https://analyst.koodous.com/rulesets/890"
strings:
$a = "HDNRQ2gOlm"
$b = "lElvyohc9Y1X+nzVUEjW8W3SbUA"
condition:
all of them
}
rule marcher3
{
meta:
author = "Antonio S. <asanchez@koodous.com>"
source = "https://analyst.koodous.com/rulesets/890"
sample1 = "087710b944c09c3905a5a9c94337a75ad88706587c10c632b78fad52ec8dfcbe"
sample2 = "fa7a9145b8fc32e3ac16fa4a4cf681b2fa5405fc154327f879eaf71dd42595c2"
strings:
$a = "certificado # 73828394"
$b = "A compania TMN informa que o vosso sistema Android tem vulnerabilidade"
condition:
all of them
}
rule marcher_v2
{
meta:
description = "This rule detects a new variant of Marcher"
sample = "27c3b0aaa2be02b4ee2bfb5b26b2b90dbefa020b9accc360232e0288ac34767f"
author = "Antonio S. <asanchez@koodous.com>"
source = "https://analyst.koodous.com/rulesets/1301"
strings:
$a = /assets\/[a-z]{1,12}.datPK/
$b = "mastercard_img"
$c = "visa_verifed"
condition:
all of them
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment