Commit Graph

449 Commits

Author SHA1 Message Date
Florian Roth
4c6377ae9a Changed tabs to spaces 2017-08-30 20:11:15 +02:00
Florian Roth
194e8b9d74 thor-hacktools.yar - some cherry picked rules 2017-08-30 20:11:00 +02:00
Florian Roth
9c5b1b1863 Malware used in South Korean campaign
https://twitter.com/eyalsela/status/900248754091167744
2017-08-23 13:21:56 +02:00
Florian Roth
2169ca69dc ShadowPad new Imphash 2017-08-23 13:21:21 +02:00
Florian Roth
cec8e3db5f Suspicious script running from http/https 2017-08-23 13:21:09 +02:00
Florian Roth
d7e3185df4 Tick Datper
http://blog.jpcert.or.jp/2017/08/detecting-datper-malware-from-proxy-logs.html
2017-08-21 17:20:01 +02:00
Florian Roth
43d129b336 PowerShdll 2017-08-21 15:03:29 +02:00
Florian Roth
737943f40c More reflective DLL loaders 2017-08-20 12:06:08 +02:00
Florian Roth
c59a0b1e80 CHAOS Payload 2017-08-18 00:58:33 +02:00
Florian Roth
b8b2628157 Makefile adjusted to reflect prebuilt YARA 3.6.2 features 2017-08-15 21:14:31 +02:00
Florian Roth
64e17301ae ShadowPad malicious nssock2.dll
https://securelist.com/shadowpad-in-corporate-networks/81432/
2017-08-15 21:12:57 +02:00
Florian Roth
b0be3141d8 Adjusted build options in make file to yara-python, rule renamed 2017-08-15 20:30:28 +02:00
Florian Roth
2444eb6d8f Pupy RAT Generic Rule 2017-08-12 21:48:18 +02:00
Florian Roth
f57c5e56ec Cobalt Strike CN group dropper, CobaltGang malware 2017-08-12 09:08:32 +02:00
Florian Roth
3be35fc5ba Improved ReflectiveLoader rule 2017-08-12 09:04:42 +02:00
Florian Roth
2091087567 Updated hacktool producers 2017-08-11 16:47:20 +02:00
Florian Roth
d0b1800ed5 Travis Tests and makefile 2017-08-11 16:00:44 +02:00
Florian Roth
f3961c6c2c Disabled rule using feature that isn't available in prebuild YARA 3.5.0 2017-08-11 16:00:29 +02:00
Florian Roth
1ae31addcb CVE-2017-9800 exploit 2017-08-11 14:03:24 +02:00
Florian Roth
c9a80a958c False Positive Reduction 2017-08-07 17:57:35 +02:00
Florian Roth
e89c558936 Agent.BTZ
http://www.intezer.com/new-variants-of-agent-btz-comrat-found/
2017-08-07 15:16:22 +02:00
Florian Roth
d85c1108ef Impacket Generic Rule 2017-08-07 14:52:45 +02:00
Florian Roth
54c32c0e90 Agent.BTZ filename IOCs 2017-08-07 14:52:34 +02:00
Florian Roth
28e5995c27 FIN7 Backdoor
https://www.proofpoint.com/us/threat-insight/post/fin7carbanak-threat-actor-unleashes-bateleur-jscript-backdoor
2017-08-07 14:32:33 +02:00
Florian Roth
1c28e32e4a Travis build notifications 2017-08-07 14:28:35 +02:00
Florian Roth
55463653e3 Build image in README 2017-08-07 14:25:11 +02:00
Florian Roth
2cebd4d54f Travis test script 2017-08-07 14:23:03 +02:00
Florian Roth
d85a7422a9 False Positive Reduction 2017-08-07 12:47:13 +02:00
Florian Roth
d4d10331a9 Zeus Panda 2017-08-05 14:54:13 +02:00
Florian Roth
06b5ea1891 False positive in still disabled rule 2017-08-05 14:53:59 +02:00
Florian Roth
44deee38c3 Typo in False Positive Condition 2017-08-02 13:28:03 +02:00
Florian Roth
c62209983b Foudre Malware (Infy)
https://researchcenter.paloaltonetworks.com/2017/08/unit42-prince-persia-ride-lightning-infy-returns-foudre/
2017-08-02 08:43:10 +02:00
Florian Roth
6243ca31f6 avdapp.dll False Positive 2017-08-01 16:21:57 +02:00
Florian Roth
ba25f2e452 Malware Unspecified 2017-08-01 14:01:53 +02:00
Florian Roth
6f7c4d9459 CactusTorch Rule 2017-07-31 14:52:02 +02:00
Florian Roth
7917b639bf Improved ReflectiveLoader Rule 2017-07-31 14:51:46 +02:00
Florian Roth
1a062a5f18 False Positive Reduction 2017-07-30 11:54:03 +02:00
Florian Roth
ce9814bdf2 Big OTX IOC update 2017-07-29 14:52:54 +02:00
Florian Roth
3d52e22109 AllTheThings 2017-07-29 13:35:07 +02:00
Florian Roth
5e8d5add05 PowerShell Empire Mods Eval 2017-07-29 13:34:49 +02:00
Florian Roth
4c5e50e9f1 MyWScript Dropper 2017-07-29 13:34:37 +02:00
Florian Roth
a8f6bb60f1 False Positive Reduction 2017-07-29 13:34:21 +02:00
Florian Roth
d776d65fdc Tick Report Hashes 2017-07-26 23:30:26 +02:00
Florian Roth
ffed1820f5 Reflective Loader rule extended 2017-07-26 03:59:31 +02:00
Florian Roth
c5b5414fd6 Wilted Tulip YARA Signatures 2017-07-25 15:24:20 +02:00
Florian Roth
2e6351ca48 Removed duplicate Invoke-Mimikatz 2017-07-23 10:15:49 -06:00
Florian Roth
cd9d7890fa Hacktool Ruler IOC 2017-07-22 16:13:24 -06:00
Florian Roth
f8447db7e9 Invoke Mimikatz and Kekeo update 2017-07-22 07:57:58 -06:00
Florian Roth
05ee5af114 Bugfix in Rule 2017-07-20 12:27:16 -06:00
Florian Roth
1f0cad89f1 Bugfixes and False Positive Reduction 2017-07-20 12:24:49 -06:00