Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
R
rules
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
rules
Commits
d9d82f1d
Commit
d9d82f1d
authored
6 years ago
by
Your Mom
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
added marap.yar signature
fixed shifu sig filename
parent
dadbcfa7
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
30 additions
and
0 deletions
+30
-0
MALW_marap.yar
malware/MALW_marap.yar
+30
-0
MALW_shifu_shiz.yar
malware/MALW_shifu_shiz.yar
+0
-0
No files found.
malware/MALW_marap.yar
0 → 100644
View file @
d9d82f1d
rule marap
{
meta:
author = " J from THL <j@techhelplist.com>"
date = "2018-08-19"
reference1 = "https://www.virustotal.com/#/file/61dfc4d535d86359c2f09dbdd8f14c0a2e6367e5bb7377812f323a94d32341ba/detection"
reference2 = "https://www.virustotal.com/#/file/c0c85f93a4f425a23c2659dce11e3b1c8b9353b566751b32fcb76b3d8b723b94/detection"
reference3 = "https://threatpost.com/highly-flexible-marap-malware-enters-the-financial-scene/136623/"
reference4 = "https://www.bleepingcomputer.com/news/security/necurs-botnet-pushing-new-marap-malware/"
version = 1
maltype = "Downloader"
filetype = "memory"
strings:
$text01 = "%02X-%02X-%02X-%02X-%02X-%02X" wide
$text02 = "%s, base=0x%p" wide
$text03 = "pid=%d" wide
$text04 = "%s %s" wide
$text05 = "%d|%d|%s|%s|%s" wide
$text06 = "%s|1|%d|%d|%d|%d|%d|%s" wide
$text07 = "%d#%s#%s#%s#%d#%s#%s#%d#%s#%s#%s#%s#%d" wide
$text08 = "%s|1|%d|%d|%d|%d|%d|%s#%s#%s#%s#%d#%d#%d" wide
$text09 = "%s|0|%d" wide
$text10 = "%llx" wide
$text11 = "%s -a" wide
condition:
7 of them
}
This diff is collapsed.
Click to expand it.
malware/MALW_shifu_shiz
→
malware/MALW_shifu_shiz
.yar
View file @
d9d82f1d
File moved
This diff is collapsed.
Click to expand it.
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment