Commit 84a474ce by jovimon

Commenting out high FP rules as per issue #39

parent 1275165d
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
import "pe" import "pe"
...@@ -82,6 +81,8 @@ rule DebuggerHiding__Active : AntiDebug DebuggerHiding { ...@@ -82,6 +81,8 @@ rule DebuggerHiding__Active : AntiDebug DebuggerHiding {
any of them any of them
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerTiming__PerformanceCounter : AntiDebug DebuggerTiming { rule DebuggerTiming__PerformanceCounter : AntiDebug DebuggerTiming {
meta: meta:
weight = 1 weight = 1
...@@ -92,7 +93,10 @@ rule DebuggerTiming__PerformanceCounter : AntiDebug DebuggerTiming { ...@@ -92,7 +93,10 @@ rule DebuggerTiming__PerformanceCounter : AntiDebug DebuggerTiming {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerTiming__Ticks : AntiDebug DebuggerTiming { rule DebuggerTiming__Ticks : AntiDebug DebuggerTiming {
meta: meta:
weight = 1 weight = 1
...@@ -103,7 +107,10 @@ rule DebuggerTiming__Ticks : AntiDebug DebuggerTiming { ...@@ -103,7 +107,10 @@ rule DebuggerTiming__Ticks : AntiDebug DebuggerTiming {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerOutput__String : AntiDebug DebuggerOutput { rule DebuggerOutput__String : AntiDebug DebuggerOutput {
meta: meta:
weight = 1 weight = 1
...@@ -114,7 +121,10 @@ rule DebuggerOutput__String : AntiDebug DebuggerOutput { ...@@ -114,7 +121,10 @@ rule DebuggerOutput__String : AntiDebug DebuggerOutput {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerException__UnhandledFilter : AntiDebug DebuggerException { rule DebuggerException__UnhandledFilter : AntiDebug DebuggerException {
meta: meta:
weight = 1 weight = 1
...@@ -125,6 +135,7 @@ rule DebuggerException__UnhandledFilter : AntiDebug DebuggerException { ...@@ -125,6 +135,7 @@ rule DebuggerException__UnhandledFilter : AntiDebug DebuggerException {
condition: condition:
any of them any of them
} }
*/
rule DebuggerException__ConsoleCtrl : AntiDebug DebuggerException { rule DebuggerException__ConsoleCtrl : AntiDebug DebuggerException {
meta: meta:
...@@ -219,7 +230,8 @@ rule SEH__vectored : AntiDebug SEH { ...@@ -219,7 +230,8 @@ rule SEH__vectored : AntiDebug SEH {
any of them any of them
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerPattern__RDTSC : AntiDebug DebuggerPattern { rule DebuggerPattern__RDTSC : AntiDebug DebuggerPattern {
meta: meta:
weight = 1 weight = 1
...@@ -230,7 +242,10 @@ rule DebuggerPattern__RDTSC : AntiDebug DebuggerPattern { ...@@ -230,7 +242,10 @@ rule DebuggerPattern__RDTSC : AntiDebug DebuggerPattern {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerPattern__CPUID : AntiDebug DebuggerPattern { rule DebuggerPattern__CPUID : AntiDebug DebuggerPattern {
meta: meta:
weight = 1 weight = 1
...@@ -241,7 +256,10 @@ rule DebuggerPattern__CPUID : AntiDebug DebuggerPattern { ...@@ -241,7 +256,10 @@ rule DebuggerPattern__CPUID : AntiDebug DebuggerPattern {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerPattern__SEH_Saves : AntiDebug DebuggerPattern { rule DebuggerPattern__SEH_Saves : AntiDebug DebuggerPattern {
meta: meta:
weight = 1 weight = 1
...@@ -252,7 +270,10 @@ rule DebuggerPattern__SEH_Saves : AntiDebug DebuggerPattern { ...@@ -252,7 +270,10 @@ rule DebuggerPattern__SEH_Saves : AntiDebug DebuggerPattern {
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule DebuggerPattern__SEH_Inits : AntiDebug DebuggerPattern { rule DebuggerPattern__SEH_Inits : AntiDebug DebuggerPattern {
meta: meta:
weight = 1 weight = 1
...@@ -263,6 +284,7 @@ rule DebuggerPattern__SEH_Inits : AntiDebug DebuggerPattern { ...@@ -263,6 +284,7 @@ rule DebuggerPattern__SEH_Inits : AntiDebug DebuggerPattern {
condition: condition:
any of them any of them
} }
*/
rule Check_Dlls rule Check_Dlls
...@@ -546,6 +568,8 @@ rule Check_OutputDebugStringA_iat ...@@ -546,6 +568,8 @@ rule Check_OutputDebugStringA_iat
pe.imports("kernel32.dll","OutputDebugStringA") pe.imports("kernel32.dll","OutputDebugStringA")
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule Check_unhandledExceptionFiler_iat { rule Check_unhandledExceptionFiler_iat {
meta: meta:
...@@ -557,7 +581,10 @@ rule Check_unhandledExceptionFiler_iat { ...@@ -557,7 +581,10 @@ rule Check_unhandledExceptionFiler_iat {
condition: condition:
pe.imports("kernel32.dll","UnhandledExceptionFilter") pe.imports("kernel32.dll","UnhandledExceptionFilter")
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule check_RaiseException_iat { rule check_RaiseException_iat {
meta: meta:
...@@ -569,6 +596,7 @@ rule check_RaiseException_iat { ...@@ -569,6 +596,7 @@ rule check_RaiseException_iat {
condition: condition:
pe.imports("kernel32.dll","RaiseException") pe.imports("kernel32.dll","RaiseException")
} }
*/
rule Check_FindWindowA_iat { rule Check_FindWindowA_iat {
......
...@@ -14,6 +14,8 @@ rule maldoc_API_hashing ...@@ -14,6 +14,8 @@ rule maldoc_API_hashing
any of them any of them
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule maldoc_function_prolog_signature rule maldoc_function_prolog_signature
{ {
meta: meta:
...@@ -27,7 +29,10 @@ rule maldoc_function_prolog_signature ...@@ -27,7 +29,10 @@ rule maldoc_function_prolog_signature
condition: condition:
any of them any of them
} }
*/
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule maldoc_structured_exception_handling rule maldoc_structured_exception_handling
{ {
meta: meta:
...@@ -38,6 +43,7 @@ rule maldoc_structured_exception_handling ...@@ -38,6 +43,7 @@ rule maldoc_structured_exception_handling
condition: condition:
any of them any of them
} }
*/
rule maldoc_indirect_function_call_1 rule maldoc_indirect_function_call_1
{ {
...@@ -131,6 +137,8 @@ rule maldoc_OLE_file_magic_number ...@@ -131,6 +137,8 @@ rule maldoc_OLE_file_magic_number
$a $a
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule maldoc_suspicious_strings rule maldoc_suspicious_strings
{ {
meta: meta:
...@@ -155,6 +163,7 @@ rule maldoc_suspicious_strings ...@@ -155,6 +163,7 @@ rule maldoc_suspicious_strings
condition: condition:
any of them any of them
} }
*/
rule mwi_document : exploitdoc rule mwi_document : exploitdoc
{ {
......
...@@ -1037,6 +1037,8 @@ rule APT1_TARSIP_MOON ...@@ -1037,6 +1037,8 @@ rule APT1_TARSIP_MOON
1 of ($s*) and 1 of ($msg*) and 1 of ($onec*) 1 of ($s*) and 1 of ($msg*) and 1 of ($onec*)
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule APT1_payloads rule APT1_payloads
{ {
meta: meta:
...@@ -1081,7 +1083,7 @@ rule APT1_payloads ...@@ -1081,7 +1083,7 @@ rule APT1_payloads
condition: condition:
1 of them 1 of them
} }
*/
rule APT1_RARSilent_EXE_PDF rule APT1_RARSilent_EXE_PDF
{ {
......
...@@ -59,6 +59,8 @@ rule Borland ...@@ -59,6 +59,8 @@ rule Borland
$patternBorland $patternBorland
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule java rule java
{ {
meta: meta:
...@@ -68,6 +70,8 @@ rule java ...@@ -68,6 +70,8 @@ rule java
condition: condition:
$patternjava $patternjava
} }
*/
rule NET rule NET
{ {
meta: meta:
...@@ -12062,7 +12066,8 @@ condition: ...@@ -12062,7 +12066,8 @@ condition:
$a0 at pe.entry_point $a0 at pe.entry_point
} }
// 20150909 - Issue #39 - Commented because of High FP rate
/*
rule Armadillov171 rule Armadillov171
{ {
meta: meta:
...@@ -12073,7 +12078,7 @@ strings: ...@@ -12073,7 +12078,7 @@ strings:
condition: condition:
$a0 at pe.entry_point $a0 at pe.entry_point
} }
*/
rule KBySV022shoooo rule KBySV022shoooo
{ {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment