Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
23aebeb8
Commit
23aebeb8
authored
Jan 10, 2017
by
mmorenog
Committed by
GitHub
Jan 10, 2017
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Create RANSOM_Comodosec.yar
parent
4dd667a3
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
41 additions
and
0 deletions
+41
-0
RANSOM_Comodosec.yar
malware/RANSOM_Comodosec.yar
+41
-0
No files found.
malware/RANSOM_Comodosec.yar
0 → 100644
View file @
23aebeb8
/*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
rule ransom_comodosec_mrcr1 {
meta:
author = " J from THL <j@techhelplist.com>"
date = "2017/01"
reference = "https://virustotal.com/en/file/75c82fd18fcf8a51bc1b32a89852d90978fa5e7a55281f42b0a1de98d14644fa/analysis/"
version = 1
maltype = "Ransomware"
filetype = "memory"
strings:
$text01 = "WebKitFormBoundary"
$text02 = "Start NetworkScan"
$text03 = "Start DriveScan"
$text04 = "Start CryptFiles"
$text05 = "cmd /c vssadmin delete shadows /all /quiet"
$text06 = "isAutorun:"
$text07 = "isNetworkScan:"
$text08 = "isUserDataLast:"
$text09 = "isCryptFileNames:"
$text10 = "isChangeFileExts:"
$text11 = "isPowerOffWindows:"
$text12 = "GatePath:"
$text13 = "GatePort:"
$text14 = "DefaultCryptKey:"
$text15 = "UserAgent:"
$text16 = "Mozilla_"
$text17 = "On Error Resume Next"
$text18 = "Content-Disposition: form-data; name=\"uid\""
$text19 = "Content-Disposition: form-data; name=\"uname\""
$text20 = "Content-Disposition: form-data; name=\"cname\""
$regx21 = /\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|/
condition:
10 of them
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment