Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
8f68fefd
Commit
8f68fefd
authored
Aug 02, 2016
by
j0sm1
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Delete COZY_FANCY_BEAR_modified_VmUpgradeHelper
Delete COZY_FANCY_BEAR_modified_VmUpgradeHelper rule
parent
56f8e2f9
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
0 additions
and
16 deletions
+0
-16
malware.yar
malware/malware.yar
+0
-16
No files found.
malware/malware.yar
View file @
8f68fefd
...
...
@@ -9874,22 +9874,6 @@ rule COZY_FANCY_BEAR_pagemgr_Hunt {
condition:
uint16
(
0
)
==
0x5a4d
and
1
of
them
}
rule
COZY_FANCY_BEAR_modified_VmUpgradeHelper
{
meta:
description =
"Detects a malicious VmUpgradeHelper.exe as mentioned in the CrowdStrike report"
author =
"Florian Roth"
reference =
"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"
date =
"2016-06-14"
strings:
$
s1 =
"VMware, Inc."
wide
fullword
$
s2 =
"Virtual hardware upgrade helper service"
fullword
wide
$
s3 =
"vmUpgradeHelper\\vmUpgradeHelper.pdb"
ascii
condition:
uint16
(
0
)
==
0x5a4d
and
filename =
=
"
VmUpgradeHelper
.
exe
"
and
not
all
of
($
s
*)
}
/*
This
Yara
ruleset
is
under
the
GNU-GPLv2
license
(
http:
//
www
.
gnu
.
org
/
licenses
/
gpl-2
.
0
.
html
)
and
open
to
any
user
or
organization
,
as
long
as
you
use
it
under
this
license
.
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment