Florian Roth
|
7c8745c59e
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
|
Florian Roth
|
5334216f73
|
Prone to false positives
https://www.virustotal.com/en/file/8e928dc79b4dd5695b1b3fcd4592b7179c2e2857a82d325d49237977636b21d2/analysis/
|
2018-03-12 14:56:19 +01:00 |
|
Florian Roth
|
2ce3e0bbaf
|
Fix to avoid too many false positives
|
2018-03-12 14:49:03 +01:00 |
|
Florian Roth
|
3018b8b551
|
Extended the APT15 rules by NCCGroups rules (revised)
https://github.com/nccgroup/Royal_APT/blob/master/signatures/apt15.yara
|
2018-03-12 12:55:33 +01:00 |
|
Florian Roth
|
07b44fe78a
|
APT15 YARA signatures
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/march/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/
|
2018-03-12 09:40:31 +01:00 |
|