Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
d9c8783f
Commit
d9c8783f
authored
Apr 08, 2017
by
Xumeiquer
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Adding malware/APT_Grasshopper.yar
parent
35e8f200
Show whitespace changes
Inline
Side-by-side
Showing
16 changed files
with
170 additions
and
13 deletions
+170
-13
antidebug_antivm.yar
Antidebug_AntiVM/antidebug_antivm.yar
+0
-0
Antidebug_AntiVM_index.yar
Antidebug_AntiVM_index.yar
+1
-1
CVE-2010-0805.yar
CVE_Rules/CVE-2010-0805.yar
+1
-1
CVE_Rules_index.yar
CVE_Rules_index.yar
+1
-1
Crypto_index.yar
Crypto_index.yar
+1
-1
Exploit-Kits_index.yar
Exploit-Kits_index.yar
+1
-1
Malicious_Documents_index.yar
Malicious_Documents_index.yar
+1
-1
Mobile_Malware_index.yar
Mobile_Malware_index.yar
+1
-1
Packers_index.yar
Packers_index.yar
+1
-1
Webshells_index.yar
Webshells_index.yar
+1
-1
email_index.yar
email_index.yar
+1
-1
index.yar
index.yar
+6
-1
index_w_mobile.yar
index_w_mobile.yar
+6
-1
APT_Grasshopper.yar
malware/APT_Grasshopper.yar
+142
-0
MALW_Corkow.yar
malware/MALW_Corkow.yar
+0
-0
malware_index.yar
malware_index.yar
+6
-1
No files found.
Antidebug_AntiVM/antidebug_antivm.yar
View file @
d9c8783f
Antidebug_AntiVM_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Antidebug_AntiVM/antidebug_antivm.yar"
CVE_Rules/CVE-2010-0805.yar
View file @
d9c8783f
...
...
@@ -8,7 +8,7 @@ rule MSIETabularActivex
strings:
$cve20100805_1 = "333C7BC4-460F-11D0-BC04-0080C7055A83" nocase fullword
$cve20100805_2 = "DataURL" nocase fullword
$cve20100805_3 =
/value\=\"http:\/\/(.*?)\"/ nocase fullword
$cve20100805_3 =
true
condition:
($cve20100805_1 and $cve20100805_3) or (all of them)
}
CVE_Rules_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./CVE_Rules/CVE-2010-0805.yar"
include "./CVE_Rules/CVE-2010-0887.yar"
...
...
Crypto_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Crypto/base64.yar"
include "./Crypto/crypto_signatures.yar"
Exploit-Kits_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Exploit-Kits/EK_Angler.yar"
include "./Exploit-Kits/EK_Blackhole.yar"
...
...
Malicious_Documents_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Malicious_Documents/Maldoc_APT_OLE_JSRat.yar"
include "./Malicious_Documents/Maldoc_Contains_VBE_File.yar"
...
...
Mobile_Malware_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Mobile_Malware/Android_adware.yar"
include "./Mobile_Malware/Android_AliPay_smsStealer.yar"
...
...
Packers_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Packers/Javascript_exploit_and_obfuscation.yar"
include "./Packers/JJencode.yar"
...
...
Webshells_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Webshells/WShell_APT_Laudanum.yar"
include "./Webshells/Wshell_ChineseSpam.yar"
...
...
email_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./email/attachment.yar"
include "./email/bank_rule.yar"
...
...
index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Antidebug_AntiVM/antidebug_antivm.yar"
include "./Crypto/base64.yar"
...
...
@@ -71,6 +71,9 @@ include "./malware/APT_fancybear_dnc.yar"
include "./malware/APT_FiveEyes.yar"
include "./malware/APT_furtim.yar"
include "./malware/APT_FVEY_ShadowBrokers_Jan17_Screen_Strings.yar"
include "./malware/APT_Grasshopper.yar"
include "./malware/APT_Greenbug.yar"
include "./malware/APT_Grizzlybear_uscert.yar"
include "./malware/APT_HackingTeam.yar"
include "./malware/APT_Hellsing.yar"
include "./malware/APT_Hikit.yar"
...
...
@@ -99,6 +102,7 @@ include "./malware/APT_PutterPanda.yar"
include "./malware/APT_Regin.yar"
include "./malware/APT_Scarab_Scieron.yar"
include "./malware/APT_Seaduke.yar"
include "./malware/APT_Shamoon_StoneDrill.yar"
include "./malware/APT_Snowglobe_Babar.yar"
include "./malware/APT_Sofacy_Bundestag.yar"
include "./malware/APT_Sofacy_Fysbis.yar"
...
...
@@ -218,6 +222,7 @@ include "./malware/MALW_Sendsafe.yar"
include "./malware/MALW_Shamoon.yar"
include "./malware/MALW_Shifu.yar"
include "./malware/MALW_Skeleton.yar"
include "./malware/MALW_Spora.yar"
include "./malware/MALW_Sqlite.yar"
include "./malware/MALW_Stealer.yar"
include "./malware/MALW_Surtr.yar"
...
...
index_w_mobile.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./Antidebug_AntiVM/antidebug_antivm.yar"
include "./Crypto/base64.yar"
...
...
@@ -71,6 +71,9 @@ include "./malware/APT_fancybear_dnc.yar"
include "./malware/APT_FiveEyes.yar"
include "./malware/APT_furtim.yar"
include "./malware/APT_FVEY_ShadowBrokers_Jan17_Screen_Strings.yar"
include "./malware/APT_Grasshopper.yar"
include "./malware/APT_Greenbug.yar"
include "./malware/APT_Grizzlybear_uscert.yar"
include "./malware/APT_HackingTeam.yar"
include "./malware/APT_Hellsing.yar"
include "./malware/APT_Hikit.yar"
...
...
@@ -99,6 +102,7 @@ include "./malware/APT_PutterPanda.yar"
include "./malware/APT_Regin.yar"
include "./malware/APT_Scarab_Scieron.yar"
include "./malware/APT_Seaduke.yar"
include "./malware/APT_Shamoon_StoneDrill.yar"
include "./malware/APT_Snowglobe_Babar.yar"
include "./malware/APT_Sofacy_Bundestag.yar"
include "./malware/APT_Sofacy_Fysbis.yar"
...
...
@@ -218,6 +222,7 @@ include "./malware/MALW_Sendsafe.yar"
include "./malware/MALW_Shamoon.yar"
include "./malware/MALW_Shifu.yar"
include "./malware/MALW_Skeleton.yar"
include "./malware/MALW_Spora.yar"
include "./malware/MALW_Sqlite.yar"
include "./malware/MALW_Stealer.yar"
include "./malware/MALW_Surtr.yar"
...
...
malware/APT_Grasshopper.yar
0 → 100644
View file @
d9c8783f
/*
Set of rules for Grasshopper APT.
Infected DLL hashes of Stolen Goods 2.1.
Ref: https://wikileaks.org/vault7/document/StolenGoods-2_1-UserGuide/StolenGoods-2_1-UserGuide.pdf
Author: Jaume Martin
Date: 07-04-2017
*/
rule Control32 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "b3dc808fc7cb4492669ec019911ef22a"
}
rule Control64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "bec30379078d5c5c7845d3be33707b89"
}
rule GH_PM32 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "2f2c5b3f3b1f97908074f526ac90a28d"
}
rule GH_PM64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "fe6c0097412b2c7b7f4b8a489004dd14"
}
rule MemStub32-GH1 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "0a579ad25fdd4db8110aac4dbb7d2da3"
}
rule MemStub32 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "8987652f26732607b769247adb4e9cce"
}
rule MemStub64-GH1 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "2350403a09e6928f0a7ba5d74da58cb9"
}
rule MemStub64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "6b5b46d3212fc3fc5b455d9efd8d3ffa"
}
rule msvcrt_Win7AMD64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "c8fc794cc5a22b5a1e0803b0b8acce77"
}
rule msvcrt_Win7x86 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "7713e5c5a48b020c9575b1b50f2e5e9e"
}
rule msvcrt_WIN8AMD64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "33c59fcdf027470e0ab1d366f54a6ebf"
}
rule msvcrt_WIN8x86 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "95490c2b284a9bb63f0ee49254ab727e"
}
rule msvcrt_WinXPx86 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "b68f72d77754f8b76168ced0924a4174"
}
rule Network_Win7AMD64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "eb92031a38f17d0e63285b5142b31966"
}
rule Network_Win7x86 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "548889baed7768b828d9c2f373abd225"
}
rule Network_WinXPx86 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "877341a16d5d223435c43a9db7f721bc"
}
rule RabbitStew32 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "a9d2e8ae5ddbf8f2842d96f7de2faef8"
}
rule RabbitStew64 {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "fa415b6280104e813770df520b303897"
}
rule Vbr {
meta:
author = "Jaume Martin"
condition:
hash.md5(0, filesize) == "961d2fd68fde2ae0b7c52e0c90767d0d"
}
malware/MALW_Corkow.yar
View file @
d9c8783f
malware_index.yar
View file @
d9c8783f
/*
Generated by Yara-Rules
On 0
4-02
-2017
On 0
8-04
-2017
*/
include "./malware/APT_APT1.yar"
include "./malware/APT_APT17.yar"
...
...
@@ -30,6 +30,9 @@ include "./malware/APT_fancybear_dnc.yar"
include "./malware/APT_FiveEyes.yar"
include "./malware/APT_furtim.yar"
include "./malware/APT_FVEY_ShadowBrokers_Jan17_Screen_Strings.yar"
include "./malware/APT_Grasshopper.yar"
include "./malware/APT_Greenbug.yar"
include "./malware/APT_Grizzlybear_uscert.yar"
include "./malware/APT_HackingTeam.yar"
include "./malware/APT_Hellsing.yar"
include "./malware/APT_Hikit.yar"
...
...
@@ -58,6 +61,7 @@ include "./malware/APT_PutterPanda.yar"
include "./malware/APT_Regin.yar"
include "./malware/APT_Scarab_Scieron.yar"
include "./malware/APT_Seaduke.yar"
include "./malware/APT_Shamoon_StoneDrill.yar"
include "./malware/APT_Snowglobe_Babar.yar"
include "./malware/APT_Sofacy_Bundestag.yar"
include "./malware/APT_Sofacy_Fysbis.yar"
...
...
@@ -177,6 +181,7 @@ include "./malware/MALW_Sendsafe.yar"
include "./malware/MALW_Shamoon.yar"
include "./malware/MALW_Shifu.yar"
include "./malware/MALW_Skeleton.yar"
include "./malware/MALW_Spora.yar"
include "./malware/MALW_Sqlite.yar"
include "./malware/MALW_Stealer.yar"
include "./malware/MALW_Surtr.yar"
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment