Commit 4189008c by jovimon

small typo on WShell_THOR_Webshells.yar

parent a5d2b00a
...@@ -4709,7 +4709,7 @@ rule multiple_webshells_0014 { ...@@ -4709,7 +4709,7 @@ rule multiple_webshells_0014 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0014 { rule multiple_webshells_0015 {
meta: meta:
description = "Semi-Auto-generated - from files wacking.php.php.txt, 1.txt, SpecialShell_99.php.php.txt, c100.php.txt" description = "Semi-Auto-generated - from files wacking.php.php.txt, 1.txt, SpecialShell_99.php.php.txt, c100.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4726,7 +4726,7 @@ rule multiple_webshells_0014 { ...@@ -4726,7 +4726,7 @@ rule multiple_webshells_0014 {
condition: condition:
1 of them 1 of them
} }
rule multiple_webshells_0015 { rule multiple_webshells_0016 {
meta: meta:
description = "Semi-Auto-generated - from files r577.php.php.txt, r57.php.php.txt, r57 Shell.php.php.txt, spy.php.php.txt, s.php.php.txt" description = "Semi-Auto-generated - from files r577.php.php.txt, r57.php.php.txt, r57 Shell.php.php.txt, spy.php.php.txt, s.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4744,7 +4744,7 @@ rule multiple_webshells_0015 { ...@@ -4744,7 +4744,7 @@ rule multiple_webshells_0015 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0016 { rule multiple_webshells_0017 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, wacking.php.php.txt, SsEs.php.php.txt, SpecialShell_99.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, wacking.php.php.txt, SsEs.php.php.txt, SpecialShell_99.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4761,7 +4761,7 @@ rule multiple_webshells_0016 { ...@@ -4761,7 +4761,7 @@ rule multiple_webshells_0016 {
condition: condition:
1 of them 1 of them
} }
rule multiple_webshells_0017 { rule multiple_webshells_0018 {
meta: meta:
description = "Semi-Auto-generated - from files webadmin.php.php.txt, iMHaPFtp.php.php.txt, Private-i3lue.php.txt" description = "Semi-Auto-generated - from files webadmin.php.php.txt, iMHaPFtp.php.php.txt, Private-i3lue.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4797,7 +4797,7 @@ rule multiple_php_webshells { ...@@ -4797,7 +4797,7 @@ rule multiple_php_webshells {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0018 { rule multiple_webshells_0019 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4813,7 +4813,7 @@ rule multiple_webshells_0018 { ...@@ -4813,7 +4813,7 @@ rule multiple_webshells_0018 {
condition: condition:
1 of them 1 of them
} }
rule multiple_webshells_0019 { rule multiple_webshells_0020 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4831,7 +4831,7 @@ rule multiple_webshells_0019 { ...@@ -4831,7 +4831,7 @@ rule multiple_webshells_0019 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0020 { rule multiple_webshells_0021 {
meta: meta:
description = "Semi-Auto-generated - from files GFS web-shell ver 3.1.7 - PRiV8.php.txt, nshell.php.php.txt, gfs_sh.php.php.txt" description = "Semi-Auto-generated - from files GFS web-shell ver 3.1.7 - PRiV8.php.txt, nshell.php.php.txt, gfs_sh.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4847,7 +4847,7 @@ rule multiple_webshells_0020 { ...@@ -4847,7 +4847,7 @@ rule multiple_webshells_0020 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0021 { rule multiple_webshells_0022 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, SpecialShell_99.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, SpecialShell_99.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4866,7 +4866,7 @@ rule multiple_webshells_0021 { ...@@ -4866,7 +4866,7 @@ rule multiple_webshells_0021 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0022 { rule multiple_webshells_0023 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt, SpecialShell_99.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, wacking.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt, SpecialShell_99.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4883,7 +4883,7 @@ rule multiple_webshells_0022 { ...@@ -4883,7 +4883,7 @@ rule multiple_webshells_0022 {
condition: condition:
all of them all of them
} }
rule multiple_webshells_0023 { rule multiple_webshells_0024 {
meta: meta:
description = "Semi-Auto-generated - from files antichat.php.php.txt, Fatalshell.php.php.txt, a_gedit.php.php.txt" description = "Semi-Auto-generated - from files antichat.php.php.txt, Fatalshell.php.php.txt, a_gedit.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4900,7 +4900,7 @@ rule multiple_webshells_0023 { ...@@ -4900,7 +4900,7 @@ rule multiple_webshells_0023 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0024 { rule multiple_webshells_0025 {
meta: meta:
description = "Semi-Auto-generated - from files c99shell_v1.0.php.php.txt, c99php.txt, SsEs.php.php.txt" description = "Semi-Auto-generated - from files c99shell_v1.0.php.php.txt, c99php.txt, SsEs.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4914,7 +4914,7 @@ rule multiple_webshells_0024 { ...@@ -4914,7 +4914,7 @@ rule multiple_webshells_0024 {
condition: condition:
1 of them 1 of them
} }
rule multiple_webshells_0025 { rule multiple_webshells_0026 {
meta: meta:
description = "Semi-Auto-generated - from files Crystal.php.txt, nshell.php.php.txt, load_shell.php.php.txt" description = "Semi-Auto-generated - from files Crystal.php.txt, nshell.php.php.txt, load_shell.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4930,7 +4930,7 @@ rule multiple_webshells_0025 { ...@@ -4930,7 +4930,7 @@ rule multiple_webshells_0025 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0026 { rule multiple_webshells_0027 {
meta: meta:
description = "Semi-Auto-generated - from files nst.php.php.txt, cybershell.php.php.txt, img.php.php.txt, nstview.php.php.txt" description = "Semi-Auto-generated - from files nst.php.php.txt, cybershell.php.php.txt, img.php.php.txt, nstview.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4947,7 +4947,7 @@ rule multiple_webshells_0026 { ...@@ -4947,7 +4947,7 @@ rule multiple_webshells_0026 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0027 { rule multiple_webshells_0028 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, dC3 Security Crew Shell PRiV.php.txt, SpecialShell_99.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, dC3 Security Crew Shell PRiV.php.txt, SpecialShell_99.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -4964,7 +4964,7 @@ rule multiple_webshells_0027 { ...@@ -4964,7 +4964,7 @@ rule multiple_webshells_0027 {
condition: condition:
all of them all of them
} }
rule multiple_webshells_0028 { rule multiple_webshells_0029 {
meta: meta:
description = "Semi-Auto-generated - from files c99shell_v1.0.php.php.txt, c99php.txt, 1.txt, c2007.php.php.txt, c100.php.txt" description = "Semi-Auto-generated - from files c99shell_v1.0.php.php.txt, c99php.txt, 1.txt, c2007.php.php.txt, c100.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -5000,7 +5000,7 @@ rule multiple_php_webshells_2 { ...@@ -5000,7 +5000,7 @@ rule multiple_php_webshells_2 {
condition: condition:
all of them all of them
} }
rule multiple_webshells_0029 { rule multiple_webshells_0030 {
meta: meta:
description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, 1.txt, SpecialShell_99.php.php.txt" description = "Semi-Auto-generated - from files w.php.php.txt, c99madshell_v2.1.php.php.txt, wacking.php.php.txt, 1.txt, SpecialShell_99.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -5019,7 +5019,7 @@ rule multiple_webshells_0029 { ...@@ -5019,7 +5019,7 @@ rule multiple_webshells_0029 {
condition: condition:
2 of them 2 of them
} }
rule multiple_webshells_0030 { rule multiple_webshells_0031 {
meta: meta:
description = "Semi-Auto-generated - from files r577.php.php.txt, r57.php.php.txt, spy.php.php.txt, s.php.php.txt" description = "Semi-Auto-generated - from files r577.php.php.txt, r57.php.php.txt, spy.php.php.txt, s.php.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
...@@ -5036,7 +5036,7 @@ rule multiple_webshells_0030 { ...@@ -5036,7 +5036,7 @@ rule multiple_webshells_0030 {
condition: condition:
1 of them 1 of them
} }
rule multiple_webshells_0031 { rule multiple_webshells_0032 {
meta: meta:
description = "Semi-Auto-generated - from files nixrem.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt, NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version.php.txt" description = "Semi-Auto-generated - from files nixrem.php.php.txt, c99shell_v1.0.php.php.txt, c99php.txt, NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version.php.txt"
author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls" author = "Neo23x0 Yara BRG + customization by Stefan -dfate- Molls"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment