Florian Roth
2f4147b6bb
Mirai Botnet Malware and Improvements
2016-10-06 08:48:52 +02:00
Florian Roth
cb0c06d4b5
Removed PHP in images sections - FPs
...
[ALERT] File Name IOC matched PATTERN:
\\(images|img|js|fonts|css|swf)\\[^\\]{,20}\.(php|jsp|jspx|asp|aspx)
MATCH:
G:\Part2\Joomla_3.3.6-Stable-Full\administrator\components\com_media\vie
ws\images\view.html.php
2016-09-16 09:26:41 +02:00
Florian Roth
eca1aacf8c
File Name Characteristics Update
2016-09-16 08:53:24 +02:00
Florian Roth
3b47e3ecd2
Antic Webshell
2016-09-11 16:43:47 +02:00
Florian Roth
dcd5367120
Webshell Name
2016-09-11 16:30:01 +02:00
Florian Roth
5f673df5f6
New Webshell Rules
2016-09-11 15:59:52 +02:00
Florian Roth
80849d2434
APT29 IOCs and Pirpi YARA Rules
2016-09-11 15:59:36 +02:00
Florian Roth
5744546da1
Fixed duplicate rule name bug
2016-09-11 15:58:57 +02:00
Florian Roth
a3ed8d33b3
New Hacktool Signatures
2016-09-10 01:16:40 +02:00
Florian Roth
bf93ee34d5
APT Buckeye
2016-09-10 01:16:28 +02:00
Florian Roth
0a1648519f
PowerShell Toolkit YARA Rules
2016-09-04 18:19:57 +02:00
Florian Roth
c8617942ce
Malware Set QA
2016-09-02 08:50:46 +02:00
Florian Roth
54f6aecd44
Removed duplicate rule
2016-08-31 14:34:21 +02:00
Florian Roth
0dfc21592c
WCE in-memory rule
2016-08-30 19:41:30 +02:00
Florian Roth
8b303b41e3
JSP Webshell Names by Cisco Talos
2016-08-30 19:41:19 +02:00
Florian Roth
ffe3aca416
Removed C2 prone to false positives
2016-08-27 00:21:23 +02:00
Florian Roth
08ebcc5b36
OTX Update and b374k back connect shell
2016-08-26 21:43:11 +02:00
Florian Roth
de84c3ae42
Device Guard Evasion
2016-08-18 08:44:27 +02:00
Florian Roth
c8d65ddbc4
PlugX Signature by Jay DiMartino
...
PDF
https://t.co/4xQ8G2mNap
2016-08-17 13:20:52 +02:00
Florian Roth
1fe1837c0f
Rule based on RC5/RC6 static key finding by Kaspersky
2016-08-17 09:32:56 +02:00
Florian Roth
cdb364758a
EQRP Extra Rules
2016-08-16 21:35:42 +02:00
Florian Roth
366abc510a
Equation Group Firewall Toolset Leak YARA Rules (First Set)
2016-08-16 20:37:13 +02:00
Florian Roth
e3ada3ee24
Renamed Webshell Rules
2016-08-16 20:32:06 +02:00
Florian Roth
9a23aba2c4
Merge pull request #3 from jonaslejon/master
...
Add new mimkatz yara-signature
2016-08-15 14:51:19 +02:00
Jonas Lejon
eea36d5ce0
Add new mimkatz yara-signature
...
From https://blog.didierstevens.com/2016/08/12/mimikatz-golden-ticket-dcsync/
2016-08-13 18:39:22 +02:00
Florian Roth
94b3b52a67
OTX - Threat Exchange Update
2016-08-12 13:56:15 +02:00
Florian Roth
754d19604d
Invoke-Mimikatz Rule
...
- useful to impress PowerShell hipsters
2016-08-10 09:35:08 +02:00
Florian Roth
2c5005744c
My Sauron Extra Rules
2016-08-10 09:34:15 +02:00
Florian Roth
dad52eb4a0
Symantec Strider IOCs and YARA Rules
2016-08-10 09:33:54 +02:00
Florian Roth
f10ecb5929
Project Sauron IOCs
2016-08-08 17:29:28 +02:00
Florian Roth
eca6d816f1
Project Sauron
2016-08-08 17:11:20 +02:00
Florian Roth
630db83081
Renamed Rule
2016-08-01 16:57:58 +02:00
Florian Roth
2db411300f
Generic Rule - Transformed Strings
2016-08-01 08:31:33 +02:00
Florian Roth
2ecac1d2c1
CKnife Webshell - by Levi
2016-07-20 13:31:11 +02:00
Florian Roth
37f8738c9e
Mimikittenz
2016-07-20 13:30:10 +02:00
Florian Roth
0c6838db9a
OTX False Positives
2016-07-20 13:29:53 +02:00
Florian Roth
7a68156e21
Furtims Parent
...
https://sentinelone.com/blogs/sfg-furtims-parent/
2016-07-17 12:59:29 +02:00
Florian Roth
09c01737cc
Filename IOCs
2016-07-16 11:19:40 +02:00
Florian Roth
e63f5f890d
Furtim Malware
2016-07-16 11:03:15 +02:00
Florian Roth
69f96e2011
Stuxnet Rules
...
- YARA Rules
- Hash IOCs
2016-07-11 19:48:03 +02:00
Florian Roth
13ab3e4876
Power PE Reflective Injection Rule by Benjamin Delpy
2016-07-11 19:47:37 +02:00
Florian Roth
e264d66a8e
Bugfix in Duqu2 Rule
2016-07-02 19:35:33 +02:00
Florian Roth
76791e7254
False Positive Reduction
2016-07-02 19:32:50 +02:00
Florian Roth
5f664abbd0
SysScan Rules by Kaspersky
2016-07-02 19:32:36 +02:00
Florian Roth
37c1835ae7
Fancy / Cozy Bear Sigs
2016-07-02 19:32:02 +02:00
Florian Roth
652a44d586
Duqu2 Sigs
2016-07-02 19:31:34 +02:00
Florian Roth
669bb122ec
OTX Update
2016-07-02 19:31:25 +02:00
Florian Roth
a248f3d8a9
Bugfix in prikormka Rules
2016-06-17 17:24:28 +02:00
Florian Roth
a1927bb1e5
FoxIT Mofang IOCs and YARA Rules
...
https://goo.gl/t3uUTG
2016-06-15 18:58:10 +02:00
Florian Roth
a3323e83aa
Sofacy Samples June 2016
...
http://researchcenter.paloaltonetworks.com/2016/06/unit42-new-sofacy-att
acks-against-us-government-agency/
2016-06-15 06:54:30 +02:00