Florian Roth
|
cfebd5ea39
|
New Equation Group Signatures
|
2017-04-17 11:18:41 +02:00 |
|
Florian Roth
|
f9d0882a35
|
Remove byte chain that is slowing down scanning
|
2017-04-13 09:52:27 +02:00 |
|
Florian Roth
|
b496ed91a6
|
Changed OLE2Link signature
|
2017-04-12 19:11:36 +02:00 |
|
Florian Roth
|
2245f5d7cb
|
Renamed - Crime > Exploit
|
2017-04-12 15:52:06 +02:00 |
|
Florian Roth
|
a431674976
|
OLE2Link Update with NVISIO rule
|
2017-04-12 15:50:29 +02:00 |
|
Florian Roth
|
629afa0835
|
RFT OLE2Link Exploit
|
2017-04-12 11:25:22 +02:00 |
|
Florian Roth
|
46568f0d03
|
Removed rule prone to false positives
|
2017-04-10 13:02:20 +02:00 |
|
Florian Roth
|
a9fc876114
|
False positive comment in EQGRP rules
|
2017-04-10 00:07:13 +02:00 |
|
Florian Roth
|
2592ea04b4
|
Equation Group Tools
|
2017-04-09 23:31:32 +02:00 |
|
Florian Roth
|
efe01ca941
|
Compiled Impacket Tools
|
2017-04-08 12:58:04 +02:00 |
|
Florian Roth
|
a0b8a9039e
|
Floxif Malware
|
2017-04-08 12:57:47 +02:00 |
|
Florian Roth
|
70dc674fc7
|
Improved Cloud Hopper Malware Sigs
|
2017-04-08 12:57:20 +02:00 |
|
Florian Roth
|
997da192a8
|
Quasar RAT
|
2017-04-07 20:41:00 +02:00 |
|
Jonas Lejon
|
716be0088c
|
C2 hosts/strings for APT10 / Cloud Hopper
|
2017-04-07 09:32:42 +02:00 |
|
Florian Roth
|
b1bb790655
|
ROKRAT
|
2017-04-05 11:23:44 +02:00 |
|
Florian Roth
|
68c999de89
|
Operation Cloud Hopper
|
2017-04-05 11:23:31 +02:00 |
|
Florian Roth
|
1c4c8df573
|
APT Moonlight Maze
|
2017-04-03 21:33:07 +02:00 |
|
Florian Roth
|
6316b06a35
|
Removed other rules from this set
|
2017-04-03 09:39:35 +02:00 |
|
Florian Roth
|
2815d65738
|
Mimipenguin
|
2017-04-01 11:56:35 +02:00 |
|
Florian Roth
|
3d505b74b3
|
Carbon - Turla - rules by ESET
|
2017-04-01 11:56:20 +02:00 |
|
Florian Roth
|
c1af41f3f9
|
False Positives
https://github.com/Neo23x0/signature-base/issues/7
|
2017-03-28 08:32:20 +02:00 |
|
Florian Roth
|
a5be8e42f6
|
Osiris Device Guard Bypass
|
2017-03-27 09:39:43 +02:00 |
|
Florian Roth
|
46444066a6
|
WMI Implant PowerShell
|
2017-03-24 17:33:26 +01:00 |
|
Florian Roth
|
8734ab6680
|
Javascript obfuscated PowerShell (droppers)
|
2017-03-24 14:52:26 +01:00 |
|
Florian Roth
|
f90da1ff10
|
WPR and BeyondExec
|
2017-03-17 16:08:44 +01:00 |
|
Florian Roth
|
f39f51d234
|
Suspicious PowerShell Invocation
|
2017-03-12 17:06:18 +01:00 |
|
Florian Roth
|
9f96ed873e
|
Bugfix - non OpenSSL binaries
|
2017-03-09 18:09:15 +01:00 |
|
Florian Roth
|
8c0de6120e
|
Removed False Positives
|
2017-03-07 21:09:38 +01:00 |
|
Florian Roth
|
b73d07558a
|
Tiny JSP Webshell YARA Rule
|
2017-03-07 11:24:48 +01:00 |
|
Florian Roth
|
48a8a94196
|
StoneDrill Threat: YARA rules and filename IOCs
|
2017-03-07 11:24:27 +01:00 |
|
Florian Roth
|
8bf466a9ac
|
Kriskynote Malware
|
2017-03-04 14:38:35 +01:00 |
|
Florian Roth
|
ea2c46df32
|
Derusbi Samples
|
2017-03-04 14:38:20 +01:00 |
|
Florian Roth
|
db4465f417
|
New Simple PHP Webshell
|
2017-03-04 14:36:07 +01:00 |
|
Florian Roth
|
c64d284911
|
ChChes - Ham / Tofu Backdoors by Cylance
|
2017-02-28 14:05:19 +01:00 |
|
Florian Roth
|
a564860d0a
|
PowerShell Rule Bugfix
|
2017-02-23 17:42:26 +01:00 |
|
Florian Roth
|
8dc9ba46d5
|
Suspicious PowerShell Code
|
2017-02-23 17:13:04 +01:00 |
|
Florian Roth
|
a4544d7c2a
|
Op Magic Hound YARA Signatures
http://researchcenter.paloaltonetworks.com/2017/02/unit42-magic-hound-campaign-attacks-saudi-targets/
|
2017-02-17 15:48:58 +01:00 |
|
Florian Roth
|
72f3c49d99
|
False positives with AV software DLLs (ESET)
|
2017-02-17 15:48:21 +01:00 |
|
Florian Roth
|
7d5227d20f
|
Removed WebShell_Generic_PHP_5 prone to false positives
|
2017-02-16 19:41:26 +01:00 |
|
Florian Roth
|
2cd4d7b422
|
Deactivated False Positives in Grizzly Steppe Rules - US CERT
|
2017-02-12 18:26:02 +01:00 |
|
Florian Roth
|
6534da8d3a
|
Cosmetics
|
2017-02-11 12:01:31 +01:00 |
|
Florian Roth
|
2f42964d1d
|
Removed duplicate rule StreamEx_ShellCrew
|
2017-02-11 11:38:12 +01:00 |
|
Florian Roth
|
8d577f57b0
|
US CERT Grizzly Steppe Report
|
2017-02-11 11:36:10 +01:00 |
|
Florian Roth
|
0069690f19
|
Remove False Positive Rules
|
2017-02-10 10:40:52 +01:00 |
|
Florian Roth
|
dd8d5585f0
|
Metasploit Payloads
|
2017-02-10 10:40:21 +01:00 |
|
Florian Roth
|
e4c17818b6
|
Shell Crew StreamEx
|
2017-02-10 10:23:29 +01:00 |
|
Florian Roth
|
ce887d4eb3
|
Rotten Potato - Avoiding False Positives
|
2017-02-07 17:58:44 +01:00 |
|
Florian Roth
|
291833ccdd
|
Winnti malware MS Report
|
2017-02-07 10:45:19 +01:00 |
|
Florian Roth
|
b80152fbc2
|
Servant Shell
|
2017-02-07 10:37:26 +01:00 |
|
Florian Roth
|
959f30b62d
|
Rotten Potato
|
2017-02-07 09:20:10 +01:00 |
|