Commit 8da187d5 by Marc Rivero López Committed by GitHub

Update APT_Emissary.yar

Fixed syntax rule
parent f55bcd25
...@@ -9,7 +9,9 @@ ...@@ -9,7 +9,9 @@
Identifier: Emissary Malware Identifier: Emissary Malware
*/ */
rule Emissary_APT_Malware_1 { rule Emissary_APT_Malware_1
{
meta: meta:
description = "Detect Emissary Malware - from samples A08E81B411.DAT, ishelp.dll" description = "Detect Emissary Malware - from samples A08E81B411.DAT, ishelp.dll"
author = "Florian Roth" author = "Florian Roth"
...@@ -29,6 +31,7 @@ rule Emissary_APT_Malware_1 { ...@@ -29,6 +31,7 @@ rule Emissary_APT_Malware_1 {
hash11 = "29d8dc863427c8e37b75eb738069c2172e79607acc7b65de6f8086ba36abf051" hash11 = "29d8dc863427c8e37b75eb738069c2172e79607acc7b65de6f8086ba36abf051"
hash12 = "98fb1d2975babc18624e3922406545458642e01360746870deee397df93f50e0" hash12 = "98fb1d2975babc18624e3922406545458642e01360746870deee397df93f50e0"
hash13 = "fbcb401cf06326ab4bb53fb9f01f1ca647f16f926811ea66984f1a1b8cf2f7bb" hash13 = "fbcb401cf06326ab4bb53fb9f01f1ca647f16f926811ea66984f1a1b8cf2f7bb"
strings: strings:
$s1 = "cmd.exe /c %s > %s" fullword ascii $s1 = "cmd.exe /c %s > %s" fullword ascii
$s2 = "execute cmd timeout." fullword ascii $s2 = "execute cmd timeout." fullword ascii
...@@ -40,6 +43,7 @@ rule Emissary_APT_Malware_1 { ...@@ -40,6 +43,7 @@ rule Emissary_APT_Malware_1 {
$s8 = "DownloadFile - exception:%s,code:0x%08x." fullword ascii $s8 = "DownloadFile - exception:%s,code:0x%08x." fullword ascii
$s9 = "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" fullword ascii $s9 = "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" fullword ascii
$s10 = "CDllApp::InitInstance() - Evnet already exists." fullword ascii $s10 = "CDllApp::InitInstance() - Evnet already exists." fullword ascii
condition: condition:
uint16(0) == 0x5a4d and filesize < 250KB and 3 of them uint16(0) == 0x5a4d and filesize < 250KB and 3 of them
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment