Florian Roth
|
db4465f417
|
New Simple PHP Webshell
|
2017-03-04 14:36:07 +01:00 |
|
Florian Roth
|
c64d284911
|
ChChes - Ham / Tofu Backdoors by Cylance
|
2017-02-28 14:05:19 +01:00 |
|
Florian Roth
|
d47b918c2e
|
OTX Update
|
2017-02-25 17:28:39 +01:00 |
|
Florian Roth
|
501eb60b33
|
OTX Update
|
2017-02-25 17:28:25 +01:00 |
|
Florian Roth
|
1b9c72cd4c
|
Minor changes
|
2017-02-25 17:28:14 +01:00 |
|
Florian Roth
|
a564860d0a
|
PowerShell Rule Bugfix
|
2017-02-23 17:42:26 +01:00 |
|
Florian Roth
|
8dc9ba46d5
|
Suspicious PowerShell Code
|
2017-02-23 17:13:04 +01:00 |
|
Florian Roth
|
a4544d7c2a
|
Op Magic Hound YARA Signatures
http://researchcenter.paloaltonetworks.com/2017/02/unit42-magic-hound-campaign-attacks-saudi-targets/
|
2017-02-17 15:48:58 +01:00 |
|
Florian Roth
|
72f3c49d99
|
False positives with AV software DLLs (ESET)
|
2017-02-17 15:48:21 +01:00 |
|
Florian Roth
|
7d5227d20f
|
Removed WebShell_Generic_PHP_5 prone to false positives
|
2017-02-16 19:41:26 +01:00 |
|
Florian Roth
|
2cd4d7b422
|
Deactivated False Positives in Grizzly Steppe Rules - US CERT
|
2017-02-12 18:26:02 +01:00 |
|
Florian Roth
|
c19ef7de0d
|
OTX Update
|
2017-02-11 12:14:11 +01:00 |
|
Florian Roth
|
6534da8d3a
|
Cosmetics
|
2017-02-11 12:01:31 +01:00 |
|
Florian Roth
|
2f42964d1d
|
Removed duplicate rule StreamEx_ShellCrew
|
2017-02-11 11:38:12 +01:00 |
|
Florian Roth
|
8d577f57b0
|
US CERT Grizzly Steppe Report
|
2017-02-11 11:36:10 +01:00 |
|
Florian Roth
|
0069690f19
|
Remove False Positive Rules
|
2017-02-10 10:40:52 +01:00 |
|
Florian Roth
|
dd8d5585f0
|
Metasploit Payloads
|
2017-02-10 10:40:21 +01:00 |
|
Florian Roth
|
e4c17818b6
|
Shell Crew StreamEx
|
2017-02-10 10:23:29 +01:00 |
|
Florian Roth
|
ce887d4eb3
|
Rotten Potato - Avoiding False Positives
|
2017-02-07 17:58:44 +01:00 |
|
Florian Roth
|
291833ccdd
|
Winnti malware MS Report
|
2017-02-07 10:45:19 +01:00 |
|
Florian Roth
|
b80152fbc2
|
Servant Shell
|
2017-02-07 10:37:26 +01:00 |
|
Florian Roth
|
959f30b62d
|
Rotten Potato
|
2017-02-07 09:20:10 +01:00 |
|
Florian Roth
|
376dcfcf5e
|
ysoserial payloads
|
2017-02-05 13:27:10 +01:00 |
|
Florian Roth
|
2a7c06adf8
|
CN APT Proofpoint ZeroT RAT
|
2017-02-05 13:26:03 +01:00 |
|
Florian Roth
|
4b1abf072e
|
New build of OTX receiver with new SDK
|
2017-02-05 13:25:01 +01:00 |
|
Florian Roth
|
a384dd543d
|
Private Rule Bugfix
|
2017-02-03 22:04:51 +01:00 |
|
Florian Roth
|
3a737e0ea8
|
FP Reduction
|
2017-02-03 21:59:32 +01:00 |
|
Florian Roth
|
6ace90f226
|
UAC Elevators Update
|
2017-02-03 21:59:14 +01:00 |
|
Florian Roth
|
d0ff872894
|
OTX Update
|
2017-02-01 17:57:23 +01:00 |
|
Florian Roth
|
896b6eeb99
|
Minor changes
|
2017-01-31 18:47:29 +01:00 |
|
Florian Roth
|
df58486639
|
FP avoidance
|
2017-01-28 12:49:14 +01:00 |
|
Florian Roth
|
6ddaf42ec3
|
Google Bot User Agent
|
2017-01-28 11:39:32 +01:00 |
|
Florian Roth
|
2ca25d1c00
|
Greenbug YARA rules
|
2017-01-26 14:00:36 +01:00 |
|
Florian Roth
|
7b16da5081
|
P0wnShell
|
2017-01-15 16:30:56 +01:00 |
|
Florian Roth
|
8b8e11282d
|
EquationGroup Rules Update
|
2017-01-14 19:38:43 +01:00 |
|
Florian Roth
|
58b7514527
|
Merge branch 'master' of https://github.com/Neo23x0/signature-base
|
2017-01-14 19:38:12 +01:00 |
|
Florian Roth
|
b5776d6971
|
Venom Linux Rootkit
|
2017-01-14 19:38:06 +01:00 |
|
Florian Roth
|
8e2e39196a
|
FScan output
|
2017-01-14 19:28:47 +01:00 |
|
Florian Roth
|
14a8c75e89
|
Merged branch master into master
|
2017-01-10 11:12:00 +01:00 |
|
Florian Roth
|
72ff9fae4d
|
ShadowBrokers Screens File Names Jan17
|
2017-01-10 11:07:04 +01:00 |
|
Florian Roth
|
eec5a37407
|
Updated Grizzly Steppe
- include more PHP Web kit Versions
|
2017-01-02 08:10:21 +01:00 |
|
Florian Roth
|
4112bc4ebf
|
Renamed APT29 YARA rule file
|
2016-12-30 10:38:03 +01:00 |
|
Florian Roth
|
eb25fa4a1c
|
Grizzly Steppe YARA Rules
|
2016-12-30 10:36:35 +01:00 |
|
Florian Roth
|
02b006d92b
|
RAT YARA rules from malwareconfig.com
Thx to Kevin Breen
|
2016-12-27 23:26:07 +01:00 |
|
Florian Roth
|
ceb33d261d
|
Telebots YARA Rule
|
2016-12-27 23:23:59 +01:00 |
|
Florian Roth
|
473ca25339
|
Promethium Neodymium YARA Rules
|
2016-12-27 23:23:46 +01:00 |
|
Florian Roth
|
54e1276cd1
|
False Positive - PipeList
|
2016-12-27 23:20:01 +01:00 |
|
Florian Roth
|
a568be5030
|
File Type Signature - Windows Registry Files
|
2016-12-27 23:19:03 +01:00 |
|
Florian Roth
|
1f78a4e321
|
OTX Update
|
2016-12-27 23:18:34 +01:00 |
|
Florian Roth
|
50f14d7d1d
|
ShadowBroker Screens File Names
|
2016-12-18 12:20:09 +01:00 |
|