Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
a00d4d64
Commit
a00d4d64
authored
Feb 27, 2016
by
mmorenog
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Update Android_FakeApps.yar
parent
10378fe2
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
8 additions
and
9 deletions
+8
-9
Android_FakeApps.yar
Mobile_Malware/Android_FakeApps.yar
+8
-9
No files found.
Mobile_Malware/Android_FakeApps.yar
View file @
a00d4d64
...
@@ -10,7 +10,7 @@
...
@@ -10,7 +10,7 @@
import "androguard"
import "androguard"
rule fake_facebook: fake
rule fake_facebook: fake
android
{
{
meta:
meta:
author = "https://twitter.com/Diviei"
author = "https://twitter.com/Diviei"
...
@@ -21,7 +21,7 @@ rule fake_facebook: fake
...
@@ -21,7 +21,7 @@ rule fake_facebook: fake
}
}
rule fake_facebook_2 : fake
rule fake_facebook_2 : fake
android
{
{
meta:
meta:
author = "https://twitter.com/plutec_net"
author = "https://twitter.com/plutec_net"
...
@@ -42,7 +42,7 @@ rule fake_facebook_2 : fake
...
@@ -42,7 +42,7 @@ rule fake_facebook_2 : fake
not androguard.certificate.issuer(/O=Facebook Mobile/)
not androguard.certificate.issuer(/O=Facebook Mobile/)
}
}
rule fake_instagram: fake
rule fake_instagram: fake
android
{
{
meta:
meta:
author = "https://twitter.com/Diviei"
author = "https://twitter.com/Diviei"
...
@@ -52,7 +52,7 @@ rule fake_instagram: fake
...
@@ -52,7 +52,7 @@ rule fake_instagram: fake
and not androguard.certificate.sha1("76D72C35164513A4A7EBA098ACCB2B22D2229CBE")
and not androguard.certificate.sha1("76D72C35164513A4A7EBA098ACCB2B22D2229CBE")
}
}
rule fake_king_games: fake
rule fake_king_games: fake
android
{
{
condition:
condition:
(androguard.app_name("AlphaBetty Saga")
(androguard.app_name("AlphaBetty Saga")
...
@@ -70,7 +70,7 @@ rule fake_king_games: fake
...
@@ -70,7 +70,7 @@ rule fake_king_games: fake
and not androguard.certificate.sha1("9E93B3336C767C3ABA6FCC4DEADA9F179EE4A05B")
and not androguard.certificate.sha1("9E93B3336C767C3ABA6FCC4DEADA9F179EE4A05B")
}
}
rule fake_market: fake
rule fake_market: fake
android
{
{
meta:
meta:
author = "https://twitter.com/plutec_net"
author = "https://twitter.com/plutec_net"
...
@@ -81,7 +81,7 @@ rule fake_market: fake
...
@@ -81,7 +81,7 @@ rule fake_market: fake
}
}
rule fake_minecraft: fake
rule fake_minecraft: fake
android
{
{
meta:
meta:
author = "https://twitter.com/plutec_net"
author = "https://twitter.com/plutec_net"
...
@@ -92,7 +92,7 @@ rule fake_minecraft: fake
...
@@ -92,7 +92,7 @@ rule fake_minecraft: fake
and not androguard.package_name("com.mojang.minecraftpe")
and not androguard.package_name("com.mojang.minecraftpe")
}
}
rule fake_whatsapp: fake
rule fake_whatsapp: fake
android
{
{
meta:
meta:
author = "https://twitter.com/Diviei"
author = "https://twitter.com/Diviei"
...
@@ -100,4 +100,4 @@ rule fake_whatsapp: fake
...
@@ -100,4 +100,4 @@ rule fake_whatsapp: fake
condition:
condition:
androguard.app_name("WhatsApp") and
androguard.app_name("WhatsApp") and
not androguard.certificate.sha1("38A0F7D505FE18FEC64FBF343ECAAAF310DBD799")
not androguard.certificate.sha1("38A0F7D505FE18FEC64FBF343ECAAAF310DBD799")
}
}
\ No newline at end of file
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment