Commit Graph

182 Commits

Author SHA1 Message Date
Florian Roth
cfebd5ea39 New Equation Group Signatures 2017-04-17 11:18:41 +02:00
Florian Roth
f9d0882a35 Remove byte chain that is slowing down scanning 2017-04-13 09:52:27 +02:00
Florian Roth
b496ed91a6 Changed OLE2Link signature 2017-04-12 19:11:36 +02:00
Florian Roth
2245f5d7cb Renamed - Crime > Exploit 2017-04-12 15:52:06 +02:00
Florian Roth
a431674976 OLE2Link Update with NVISIO rule 2017-04-12 15:50:29 +02:00
Florian Roth
629afa0835 RFT OLE2Link Exploit 2017-04-12 11:25:22 +02:00
Florian Roth
46568f0d03 Removed rule prone to false positives 2017-04-10 13:02:20 +02:00
Florian Roth
a9fc876114 False positive comment in EQGRP rules 2017-04-10 00:07:13 +02:00
Florian Roth
2592ea04b4 Equation Group Tools 2017-04-09 23:31:32 +02:00
Florian Roth
efe01ca941 Compiled Impacket Tools 2017-04-08 12:58:04 +02:00
Florian Roth
a0b8a9039e Floxif Malware 2017-04-08 12:57:47 +02:00
Florian Roth
70dc674fc7 Improved Cloud Hopper Malware Sigs 2017-04-08 12:57:20 +02:00
Florian Roth
997da192a8 Quasar RAT 2017-04-07 20:41:00 +02:00
Jonas Lejon
716be0088c C2 hosts/strings for APT10 / Cloud Hopper 2017-04-07 09:32:42 +02:00
Florian Roth
b1bb790655 ROKRAT 2017-04-05 11:23:44 +02:00
Florian Roth
68c999de89 Operation Cloud Hopper 2017-04-05 11:23:31 +02:00
Florian Roth
1c4c8df573 APT Moonlight Maze 2017-04-03 21:33:07 +02:00
Florian Roth
6316b06a35 Removed other rules from this set 2017-04-03 09:39:35 +02:00
Florian Roth
2815d65738 Mimipenguin 2017-04-01 11:56:35 +02:00
Florian Roth
3d505b74b3 Carbon - Turla - rules by ESET 2017-04-01 11:56:20 +02:00
Florian Roth
c1af41f3f9 False Positives
https://github.com/Neo23x0/signature-base/issues/7
2017-03-28 08:32:20 +02:00
Florian Roth
a5be8e42f6 Osiris Device Guard Bypass 2017-03-27 09:39:43 +02:00
Florian Roth
46444066a6 WMI Implant PowerShell 2017-03-24 17:33:26 +01:00
Florian Roth
8734ab6680 Javascript obfuscated PowerShell (droppers) 2017-03-24 14:52:26 +01:00
Florian Roth
f90da1ff10 WPR and BeyondExec 2017-03-17 16:08:44 +01:00
Florian Roth
f39f51d234 Suspicious PowerShell Invocation 2017-03-12 17:06:18 +01:00
Florian Roth
9f96ed873e Bugfix - non OpenSSL binaries 2017-03-09 18:09:15 +01:00
Florian Roth
8c0de6120e Removed False Positives 2017-03-07 21:09:38 +01:00
Florian Roth
b73d07558a Tiny JSP Webshell YARA Rule 2017-03-07 11:24:48 +01:00
Florian Roth
48a8a94196 StoneDrill Threat: YARA rules and filename IOCs 2017-03-07 11:24:27 +01:00
Florian Roth
8bf466a9ac Kriskynote Malware 2017-03-04 14:38:35 +01:00
Florian Roth
ea2c46df32 Derusbi Samples 2017-03-04 14:38:20 +01:00
Florian Roth
db4465f417 New Simple PHP Webshell 2017-03-04 14:36:07 +01:00
Florian Roth
c64d284911 ChChes - Ham / Tofu Backdoors by Cylance 2017-02-28 14:05:19 +01:00
Florian Roth
a564860d0a PowerShell Rule Bugfix 2017-02-23 17:42:26 +01:00
Florian Roth
8dc9ba46d5 Suspicious PowerShell Code 2017-02-23 17:13:04 +01:00
Florian Roth
a4544d7c2a Op Magic Hound YARA Signatures
http://researchcenter.paloaltonetworks.com/2017/02/unit42-magic-hound-campaign-attacks-saudi-targets/
2017-02-17 15:48:58 +01:00
Florian Roth
72f3c49d99 False positives with AV software DLLs (ESET) 2017-02-17 15:48:21 +01:00
Florian Roth
7d5227d20f Removed WebShell_Generic_PHP_5 prone to false positives 2017-02-16 19:41:26 +01:00
Florian Roth
2cd4d7b422 Deactivated False Positives in Grizzly Steppe Rules - US CERT 2017-02-12 18:26:02 +01:00
Florian Roth
6534da8d3a Cosmetics 2017-02-11 12:01:31 +01:00
Florian Roth
2f42964d1d Removed duplicate rule StreamEx_ShellCrew 2017-02-11 11:38:12 +01:00
Florian Roth
8d577f57b0 US CERT Grizzly Steppe Report 2017-02-11 11:36:10 +01:00
Florian Roth
0069690f19 Remove False Positive Rules 2017-02-10 10:40:52 +01:00
Florian Roth
dd8d5585f0 Metasploit Payloads 2017-02-10 10:40:21 +01:00
Florian Roth
e4c17818b6 Shell Crew StreamEx 2017-02-10 10:23:29 +01:00
Florian Roth
ce887d4eb3 Rotten Potato - Avoiding False Positives 2017-02-07 17:58:44 +01:00
Florian Roth
291833ccdd Winnti malware MS Report 2017-02-07 10:45:19 +01:00
Florian Roth
b80152fbc2 Servant Shell 2017-02-07 10:37:26 +01:00
Florian Roth
959f30b62d Rotten Potato 2017-02-07 09:20:10 +01:00