- 07 Jan, 2020 8 commits
-
-
Add MALW_FUDCrypt.yar and MALW_MSILStealer.yar
jovimon authored -
jovimon authored
-
jovimon authored
-
Create RANSOM_Maze.yar
jovimon authored -
Add Chacha stream cipher constants for 128-bit and 256-bit key
jovimon authored -
jovimon authored
-
Update WhiskeyBravo_mod.yara
jovimon authored -
Add SHA2 / BLAKE2 / Argon2 IVs
jovimon authored
-
- 28 Dec, 2019 1 commit
-
-
Sylvain Pelissier authored
-
- 12 Dec, 2019 1 commit
-
-
41badf10ef6f469dd1c3be201aba809f9c42f86ad77d7f83bc3895bfa289c635 is WhiskeyDelta
Rony authored
-
- 02 Dec, 2019 1 commit
-
-
Sylvain Pelissier authored
-
- 26 Nov, 2019 1 commit
-
-
Xumeiquer authored
-
- 24 Nov, 2019 1 commit
-
-
Bart authored
-
- 22 Nov, 2019 2 commits
- 19 Nov, 2019 2 commits
- 11 Sep, 2019 1 commit
-
-
j0sm1 authored
-
- 14 Aug, 2019 1 commit
-
-
New rules for 2 malware families MedussaHTTP bot and AlMashreq agent.
j0sm1 authored
-
- 13 Aug, 2019 2 commits
-
-
Jamie Bennion authored
-
sync my repo with the reference base yara-rules
techhelplist authored
-
- 07 May, 2019 1 commit
-
-
Syntax error fixed
j0sm1 authored
-
- 27 Mar, 2019 3 commits
-
-
Xumeiquer authored
-
Xumeiquer authored
-
Fix suspicious_packer_section rule
Jaume Martin authored
-
- 24 Mar, 2019 1 commit
-
-
1. The check of first two bytes was wrong for PE files. 2. Limit the search to the first 1024 bytes of the files, which should be sufficient to match on section names.
Frank Poz authored
-
- 17 Mar, 2019 9 commits
- 14 Mar, 2019 1 commit
-
-
The Capabilities ruleset contains rules that do not fit into one of the other categories but are useful information for analysis. The initial rules are those from the AntiDebug AntiVM ruleset that are not related to anti-analysis techniques. Fixes #316
Frank Poz authored
-
- 08 Mar, 2019 1 commit
-
-
Bart authored
-
- 26 Feb, 2019 2 commits
-
-
Jaume Martin authored
-
Better SEH Detection
Jaume Martin authored
-
- 21 Feb, 2019 1 commit
-
-
I have improved the @naxonez rules. These should be lower FP. Please let me know.
Malware Utkonos authored
-