Commit 2e9fc310 by Ryan B

rename malware rules missing .yar extension and add to index.

Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
parent 0de1aee4
...@@ -52,6 +52,7 @@ include "./malware/APT_Minidionis.yar" ...@@ -52,6 +52,7 @@ include "./malware/APT_Minidionis.yar"
include "./malware/APT_Mirage.yar" include "./malware/APT_Mirage.yar"
include "./malware/APT_Molerats.yar" include "./malware/APT_Molerats.yar"
include "./malware/APT_Mongall.yar" include "./malware/APT_Mongall.yar"
include "./malware/APT_MoonlightMaze.yar"
include "./malware/APT_NGO.yar" include "./malware/APT_NGO.yar"
include "./malware/APT_OPCleaver.yar" include "./malware/APT_OPCleaver.yar"
include "./malware/APT_Oilrig.yar" include "./malware/APT_Oilrig.yar"
...@@ -65,8 +66,11 @@ include "./malware/APT_Platinum.yar" ...@@ -65,8 +66,11 @@ include "./malware/APT_Platinum.yar"
include "./malware/APT_Poseidon_Group.yar" include "./malware/APT_Poseidon_Group.yar"
include "./malware/APT_Prikormka.yar" include "./malware/APT_Prikormka.yar"
include "./malware/APT_PutterPanda.yar" include "./malware/APT_PutterPanda.yar"
include "./malware/APT_RedLeaves.yar"
include "./malware/APT_Regin.yar" include "./malware/APT_Regin.yar"
include "./malware/APT_RemSec.yar" include "./malware/APT_RemSec.yar"
include "./malware/APT_Sauron.yar"
include "./malware/APT_Sauron_extras.yar
include "./malware/APT_Scarab_Scieron.yar" include "./malware/APT_Scarab_Scieron.yar"
include "./malware/APT_Seaduke.yar" include "./malware/APT_Seaduke.yar"
include "./malware/APT_Shamoon_StoneDrill.yar" include "./malware/APT_Shamoon_StoneDrill.yar"
...@@ -128,6 +132,7 @@ include "./malware/MALW_Derkziel.yar" ...@@ -128,6 +132,7 @@ include "./malware/MALW_Derkziel.yar"
include "./malware/MALW_Dexter.yar" include "./malware/MALW_Dexter.yar"
include "./malware/MALW_DiamondFox.yar" include "./malware/MALW_DiamondFox.yar"
include "./malware/MALW_DirtJumper.yar" include "./malware/MALW_DirtJumper.yar"
include "./malware/MALW_Eicar.yar"
include "./malware/MALW_Elex.yar" include "./malware/MALW_Elex.yar"
include "./malware/MALW_Elknot.yar" include "./malware/MALW_Elknot.yar"
include "./malware/MALW_Emotet.yar" include "./malware/MALW_Emotet.yar"
...@@ -160,6 +165,7 @@ include "./malware/MALW_Jolob_Backdoor.yar" ...@@ -160,6 +165,7 @@ include "./malware/MALW_Jolob_Backdoor.yar"
include "./malware/MALW_KINS.yar" include "./malware/MALW_KINS.yar"
include "./malware/MALW_Kelihos.yar" include "./malware/MALW_Kelihos.yar"
include "./malware/MALW_KeyBase.yar" include "./malware/MALW_KeyBase.yar"
include "./malware/MALW_kirbi_mimikatz.yar"
include "./malware/MALW_Korlia.yar" include "./malware/MALW_Korlia.yar"
include "./malware/MALW_Korplug.yar" include "./malware/MALW_Korplug.yar"
include "./malware/MALW_Kovter.yar" include "./malware/MALW_Kovter.yar"
...@@ -201,6 +207,7 @@ include "./malware/MALW_Odinaff.yar" ...@@ -201,6 +207,7 @@ include "./malware/MALW_Odinaff.yar"
include "./malware/MALW_Olyx.yar" include "./malware/MALW_Olyx.yar"
include "./malware/MALW_PE_sections.yar" include "./malware/MALW_PE_sections.yar"
include "./malware/MALW_PittyTiger.yar" include "./malware/MALW_PittyTiger.yar"
include "./malware/MALW_PolishBankRat.yar"
include "./malware/MALW_Ponmocup.yar" include "./malware/MALW_Ponmocup.yar"
include "./malware/MALW_Pony.yar" include "./malware/MALW_Pony.yar"
include "./malware/MALW_Predator.yar" include "./malware/MALW_Predator.yar"
...@@ -313,6 +320,7 @@ include "./malware/POS_MalumPOS.yar" ...@@ -313,6 +320,7 @@ include "./malware/POS_MalumPOS.yar"
include "./malware/POS_Mozart.yar" include "./malware/POS_Mozart.yar"
include "./malware/RANSOM_.CRYPTXXX.yar" include "./malware/RANSOM_.CRYPTXXX.yar"
include "./malware/RANSOM_777.yar" include "./malware/RANSOM_777.yar"
include "./malware/RANSOM_acroware.yar"
include "./malware/RANSOM_Alpha.yar" include "./malware/RANSOM_Alpha.yar"
include "./malware/RANSOM_BadRabbit.yar" include "./malware/RANSOM_BadRabbit.yar"
include "./malware/RANSOM_Cerber.yar" include "./malware/RANSOM_Cerber.yar"
...@@ -325,13 +333,17 @@ include "./malware/RANSOM_DoublePulsar_Petya.yar" ...@@ -325,13 +333,17 @@ include "./malware/RANSOM_DoublePulsar_Petya.yar"
include "./malware/RANSOM_Erebus.yar" include "./malware/RANSOM_Erebus.yar"
include "./malware/RANSOM_GPGQwerty.yar" include "./malware/RANSOM_GPGQwerty.yar"
include "./malware/RANSOM_GoldenEye.yar" include "./malware/RANSOM_GoldenEye.yar"
include "./malware/RANSOM_locdoor.yar"
include "./malware/RANSOM_Locky.yar" include "./malware/RANSOM_Locky.yar"
include "./malware/RANSOM_MS17-010_Wannacrypt.yar" include "./malware/RANSOM_MS17-010_Wannacrypt.yar"
include "./malware/RANSOM_Maze.yar" include "./malware/RANSOM_Maze.yar"
include "./malware/RANSOM_PetrWrap.yar" include "./malware/RANSOM_PetrWrap.yar"
include "./malware/RANSOM_Petya.yar" include "./malware/RANSOM_Petya.yar"
include "./malware/RANSOM_Pico.yar"
include "./malware/RANSOM_SamSam.yar" include "./malware/RANSOM_SamSam.yar"
include "./malware/RANSOM_Satana.yar" include "./malware/RANSOM_Satana.yar"
include "./malware/RANSOM_Shiva.yar"
include "./malware/RANSOM_shrug2.yar"
include "./malware/RANSOM_Sigma.yar" include "./malware/RANSOM_Sigma.yar"
include "./malware/RANSOM_Snake.yar" include "./malware/RANSOM_Snake.yar"
include "./malware/RANSOM_Stampado.yar" include "./malware/RANSOM_Stampado.yar"
...@@ -360,6 +372,7 @@ include "./malware/RAT_Meterpreter_Reverse_Tcp.yar" ...@@ -360,6 +372,7 @@ include "./malware/RAT_Meterpreter_Reverse_Tcp.yar"
include "./malware/RAT_Nanocore.yar" include "./malware/RAT_Nanocore.yar"
include "./malware/RAT_NetwiredRC.yar" include "./malware/RAT_NetwiredRC.yar"
include "./malware/RAT_Njrat.yar" include "./malware/RAT_Njrat.yar"
include "./malware/RAT_Orcus.yar"
include "./malware/RAT_PlugX.yar" include "./malware/RAT_PlugX.yar"
include "./malware/RAT_PoetRATDoc.yar" include "./malware/RAT_PoetRATDoc.yar"
include "./malware/RAT_PoetRATPython.yar" include "./malware/RAT_PoetRATPython.yar"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment