This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
*/
rule apt_sofacy_xtunnel {
rule apt_sofacy_xtunnel : APT28 Sofacy {
meta:
meta:
author = "Claudio Guarnieri"
author = "Claudio Guarnieri"
description = "Sofacy Malware - German Bundestag"
description = "Sofacy Malware - German Bundestag"
...
@@ -24,7 +24,7 @@ rule apt_sofacy_xtunnel {
...
@@ -24,7 +24,7 @@ rule apt_sofacy_xtunnel {
((uint16(0) == 0x5A4D) or (uint16(0) == 0xCFD0)) and (($xaps) or (all of ($variant1*)) or (all of ($variant2*)) or (6 of ($mix*)))
((uint16(0) == 0x5A4D) or (uint16(0) == 0xCFD0)) and (($xaps) or (all of ($variant1*)) or (all of ($variant2*)) or (6 of ($mix*)))
}
}
rule Sofacy_Bundestag_Winexe {
rule Sofacy_Bundestag_Winexe : APT28 Sofacy {
meta:
meta:
description = "Winexe tool used by Sofacy group in Bundestag APT"
description = "Winexe tool used by Sofacy group in Bundestag APT"
author = "Florian Roth"
author = "Florian Roth"
...
@@ -39,7 +39,7 @@ rule Sofacy_Bundestag_Winexe {
...
@@ -39,7 +39,7 @@ rule Sofacy_Bundestag_Winexe {
uint16(0) == 0x5a4d and filesize < 115KB and all of them
uint16(0) == 0x5a4d and filesize < 115KB and all of them