Commit faa7876a by mmorenog Committed by GitHub

Create Android_Godless.yar

parent c264181a
/*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
import "androguard"
rule Android_Godlike
{
meta:
author = "Jacob Soo Lead Re"
date = "01-July-2016"
description = "This rule will be able to tag all the samples with local exploits."
source = "http://blog.trendmicro.com/trendlabs-security-intelligence/godless-mobile-malware-uses-multiple-exploits-root-devices/"
strings:
$a = "libgodlikelib.so"
condition:
(androguard.service(/godlike\.s/i) and
androguard.service(/godlike\.g/i) and
androguard.receiver(/godlike\.e/i)) or
$a
}
rule Android_Godlike_2
{
meta:
author = "Jacob Soo Lead Re"
date = "01-July-2016"
description = "This rule will be able to tag all the samples with remote exploits."
source = "http://blog.trendmicro.com/trendlabs-security-intelligence/godless-mobile-malware-uses-multiple-exploits-root-devices/"
strings:
$a_1 = "libroot.so"
$a_2 = "silent91_arm_bin.root"
$a_3 = "libr.so"
$a_4 = "libpl_droidsonroids_gif.so"
condition:
(androguard.service(/FastInstallService/i) and
androguard.service(/DownloadService/i)) and
any of ($a_*)
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment