Commit 8b46f9be by Yara Rules

Added androguard disclaimer to mobile malware files

parent da8975e7
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule koodous : official rule koodous : official
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule koodous : ClickFraud AdFraud SMS Downloader_Trojan rule koodous : ClickFraud AdFraud SMS Downloader_Trojan
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule Dendroid rule Dendroid
...@@ -8,7 +7,7 @@ rule Dendroid ...@@ -8,7 +7,7 @@ rule Dendroid
meta: meta:
author = "https://twitter.com/jsmesa" author = "https://twitter.com/jsmesa"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "Dendroid RAT" description = "Dendroid RAT"
strings: strings:
$s1 = "/upload-pictures.php?" $s1 = "/upload-pictures.php?"
$s2 = "Opened Dialog:" $s2 = "Opened Dialog:"
...@@ -25,7 +24,7 @@ rule Dendroid_2 ...@@ -25,7 +24,7 @@ rule Dendroid_2
meta: meta:
author = "https://twitter.com/jsmesa" author = "https://twitter.com/jsmesa"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "Dendroid evidences via Droidian service" description = "Dendroid evidences via Droidian service"
strings: strings:
$a = "Droidian" $a = "Droidian"
$b = "DroidianService" $b = "DroidianService"
...@@ -39,7 +38,7 @@ rule Dendroid_3 ...@@ -39,7 +38,7 @@ rule Dendroid_3
meta: meta:
author = "https://twitter.com/jsmesa" author = "https://twitter.com/jsmesa"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "Dendroid evidences via ServiceReceiver" description = "Dendroid evidences via ServiceReceiver"
strings: strings:
$1 = "ServiceReceiver" $1 = "ServiceReceiver"
$2 = "Dendroid" $2 = "Dendroid"
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule whatsapp:fake rule whatsapp:fake
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule fraudulents_2 : certificates rule fraudulents_2 : certificates
......
...@@ -2,6 +2,9 @@ ...@@ -2,6 +2,9 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
import "cuckoo"
rule ransomware : svpeng rule ransomware : svpeng
{ {
meta: meta:
...@@ -39,7 +42,6 @@ rule Ransomware : banker ...@@ -39,7 +42,6 @@ rule Ransomware : banker
condition: condition:
any of ($strings_*) any of ($strings_*)
} }
import "cuckoo"
rule koler_domains rule koler_domains
{ {
......
...@@ -3,8 +3,16 @@ ...@@ -3,8 +3,16 @@
*/ */
import "androguard" /*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/
import "androguard"
rule tinhvan rule tinhvan
{ {
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule BaDoink : official rule BaDoink : official
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule adware : ads rule adware : ads
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule leadbolt : advertising rule leadbolt : advertising
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule sensual_woman: chinese rule sensual_woman: chinese
...@@ -19,8 +28,6 @@ rule sensual_woman: chinese ...@@ -19,8 +28,6 @@ rule sensual_woman: chinese
or androguard.package_name(/com.video.uiA/i) or androguard.package_name(/com.video.uiA/i)
} }
import "androguard"
rule chinese2 : sms_sender rule chinese2 : sms_sender
{ {
meta: meta:
...@@ -35,7 +42,6 @@ rule chinese2 : sms_sender ...@@ -35,7 +42,6 @@ rule chinese2 : sms_sender
androguard.package_name(/kr.mlffstrvwb.mu/) androguard.package_name(/kr.mlffstrvwb.mu/)
} }
import "androguard"
rule chinese_porn : SMSSend rule chinese_porn : SMSSend
{ {
meta: meta:
...@@ -46,7 +52,6 @@ rule chinese_porn : SMSSend ...@@ -46,7 +52,6 @@ rule chinese_porn : SMSSend
androguard.package_name("com.shenqi.video.nfkw.neim") androguard.package_name("com.shenqi.video.nfkw.neim")
} }
import "androguard"
rule chineseporn4 : SMSSend rule chineseporn4 : SMSSend
{ {
meta: meta:
...@@ -57,8 +62,6 @@ rule chineseporn4 : SMSSend ...@@ -57,8 +62,6 @@ rule chineseporn4 : SMSSend
androguard.package_name("org.mygson.videoa.zw") androguard.package_name("org.mygson.videoa.zw")
} }
import "androguard"
rule chineseporn5 : SMSSend rule chineseporn5 : SMSSend
{ {
meta: meta:
...@@ -72,5 +75,4 @@ rule chineseporn5 : SMSSend ...@@ -72,5 +75,4 @@ rule chineseporn5 : SMSSend
androguard.package_name("com.android.sxye.wwwl") or androguard.package_name("com.android.sxye.wwwl") or
androguard.certificate.issuer(/llfovtfttfldddcffffhhh/) androguard.certificate.issuer(/llfovtfttfldddcffffhhh/)
} }
\ No newline at end of file
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as
long as you use it under this license. long as you use it under this license.
*/ */
rule dropper:realshell { rule dropper:realshell {
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule facebook : fakebook rule facebook : fakebook
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule minecraft rule minecraft
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard" import "androguard"
rule hacking_team : stcert rule hacking_team : stcert
{ {
meta: meta:
...@@ -44,6 +51,4 @@ rule hacking_team : stcert ...@@ -44,6 +51,4 @@ rule hacking_team : stcert
//97257C6D8F6DA60EA27D2388D9AE252657FF3304 this certification could be stolen //97257C6D8F6DA60EA27D2388D9AE252657FF3304 this certification could be stolen
//03EA873D5D13707B0C278A0055E452416054E27B this certification could be stolen //03EA873D5D13707B0C278A0055E452416054E27B this certification could be stolen
//B8D5E3F0BCAD2EB03BB34AEE2B3F63FC5162C56B this certification could be stolen //B8D5E3F0BCAD2EB03BB34AEE2B3F63FC5162C56B this certification could be stolen
} }
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard"
rule smspay_chinnese : hejupay rule smspay_chinnese : hejupay
{ {
meta: meta:
...@@ -17,7 +28,6 @@ rule smspay_chinnese : hejupay ...@@ -17,7 +28,6 @@ rule smspay_chinnese : hejupay
$a or $b $a or $b
} }
import "androguard"
rule smsfraud : ganga rule smsfraud : ganga
{ {
...@@ -39,7 +49,6 @@ rule smsfraud : ganga ...@@ -39,7 +49,6 @@ rule smsfraud : ganga
} }
import "androguard"
rule sms_fraud : MSACM32 rule sms_fraud : MSACM32
{ {
...@@ -79,9 +88,6 @@ rule sms_fraud_gen : generic ...@@ -79,9 +88,6 @@ rule sms_fraud_gen : generic
androguard.permission(/android.permission.SEND_SMS/) androguard.permission(/android.permission.SEND_SMS/)
} }
import "androguard"
rule smsfraud rule smsfraud
{ {
meta: meta:
......
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
/*
Androguard module used in this rule file is under development by people at https://koodous.com/. Unfortunately it isn't published yet.
We will update this rule file and our website once the module is published.
Androguard module is based on androguard tool available @ https://github.com/androguard/androguard.
https://koodous.com/ is a very nice android malware analysis platform you can check out if you want to analyze your APK.
*/ */
import "androguard"
rule Android_Malware : iBanking rule Android_Malware : iBanking
{ {
meta: meta:
...@@ -22,8 +33,6 @@ rule Android_Malware : iBanking ...@@ -22,8 +33,6 @@ rule Android_Malware : iBanking
($pk at 0 and 2 of ($file*) and ($string1 or $string2)) ($pk at 0 and 2 of ($file*) and ($string1 or $string2))
} }
import "androguard"
rule Installer: banker rule Installer: banker
{ {
meta: meta:
...@@ -33,5 +42,4 @@ rule Installer: banker ...@@ -33,5 +42,4 @@ rule Installer: banker
condition: condition:
androguard.package_name("Jk7H.PwcD") androguard.package_name("Jk7H.PwcD")
} }
\ No newline at end of file
/* /*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule xbot007 rule xbot007
{ {
meta: meta:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment