Commit Graph

533 Commits

Author SHA1 Message Date
Florian Roth
d0b1800ed5 Travis Tests and makefile 2017-08-11 16:00:44 +02:00
Florian Roth
f3961c6c2c Disabled rule using feature that isn't available in prebuild YARA 3.5.0 2017-08-11 16:00:29 +02:00
Florian Roth
1ae31addcb CVE-2017-9800 exploit 2017-08-11 14:03:24 +02:00
Florian Roth
c9a80a958c False Positive Reduction 2017-08-07 17:57:35 +02:00
Florian Roth
e89c558936 Agent.BTZ
http://www.intezer.com/new-variants-of-agent-btz-comrat-found/
2017-08-07 15:16:22 +02:00
Florian Roth
d85c1108ef Impacket Generic Rule 2017-08-07 14:52:45 +02:00
Florian Roth
54c32c0e90 Agent.BTZ filename IOCs 2017-08-07 14:52:34 +02:00
Florian Roth
28e5995c27 FIN7 Backdoor
https://www.proofpoint.com/us/threat-insight/post/fin7carbanak-threat-actor-unleashes-bateleur-jscript-backdoor
2017-08-07 14:32:33 +02:00
Florian Roth
1c28e32e4a Travis build notifications 2017-08-07 14:28:35 +02:00
Florian Roth
55463653e3 Build image in README 2017-08-07 14:25:11 +02:00
Florian Roth
2cebd4d54f Travis test script 2017-08-07 14:23:03 +02:00
Florian Roth
d85a7422a9 False Positive Reduction 2017-08-07 12:47:13 +02:00
Florian Roth
d4d10331a9 Zeus Panda 2017-08-05 14:54:13 +02:00
Florian Roth
06b5ea1891 False positive in still disabled rule 2017-08-05 14:53:59 +02:00
Florian Roth
44deee38c3 Typo in False Positive Condition 2017-08-02 13:28:03 +02:00
Florian Roth
c62209983b Foudre Malware (Infy)
https://researchcenter.paloaltonetworks.com/2017/08/unit42-prince-persia-ride-lightning-infy-returns-foudre/
2017-08-02 08:43:10 +02:00
Florian Roth
6243ca31f6 avdapp.dll False Positive 2017-08-01 16:21:57 +02:00
Florian Roth
ba25f2e452 Malware Unspecified 2017-08-01 14:01:53 +02:00
Florian Roth
6f7c4d9459 CactusTorch Rule 2017-07-31 14:52:02 +02:00
Florian Roth
7917b639bf Improved ReflectiveLoader Rule 2017-07-31 14:51:46 +02:00
Florian Roth
1a062a5f18 False Positive Reduction 2017-07-30 11:54:03 +02:00
Florian Roth
ce9814bdf2 Big OTX IOC update 2017-07-29 14:52:54 +02:00
Florian Roth
3d52e22109 AllTheThings 2017-07-29 13:35:07 +02:00
Florian Roth
5e8d5add05 PowerShell Empire Mods Eval 2017-07-29 13:34:49 +02:00
Florian Roth
4c5e50e9f1 MyWScript Dropper 2017-07-29 13:34:37 +02:00
Florian Roth
a8f6bb60f1 False Positive Reduction 2017-07-29 13:34:21 +02:00
Florian Roth
d776d65fdc Tick Report Hashes 2017-07-26 23:30:26 +02:00
Florian Roth
ffed1820f5 Reflective Loader rule extended 2017-07-26 03:59:31 +02:00
Florian Roth
c5b5414fd6 Wilted Tulip YARA Signatures 2017-07-25 15:24:20 +02:00
Florian Roth
2e6351ca48 Removed duplicate Invoke-Mimikatz 2017-07-23 10:15:49 -06:00
Florian Roth
cd9d7890fa Hacktool Ruler IOC 2017-07-22 16:13:24 -06:00
Florian Roth
f8447db7e9 Invoke Mimikatz and Kekeo update 2017-07-22 07:57:58 -06:00
Florian Roth
05ee5af114 Bugfix in Rule 2017-07-20 12:27:16 -06:00
Florian Roth
1f0cad89f1 Bugfixes and False Positive Reduction 2017-07-20 12:24:49 -06:00
Florian Roth
f349e2df17 PS AMSI Bypass, JS Obfuscation/Dropbox, MSHTA Bypass 2017-07-19 19:50:59 -06:00
Florian Roth
b98ad7989d Renamed rule 2017-07-19 19:50:26 -06:00
Florian Roth
0e05adc80d Exploit code CVE-2015-2545 2017-07-19 19:47:39 -06:00
Florian Roth
990e20e3b6 Mimikatz Rules synct, SecurityXploded rule 2017-07-19 19:09:25 -06:00
Florian Roth
a5c774788c POSHSPY malware 2017-07-19 11:40:16 -06:00
Florian Roth
bfd2d404dc Merge pull request #17 from wesdawg/patch-1
WildNeutron False Positive Fix
2017-07-19 10:18:24 -06:00
Florian Roth
b4b45111a8 Unspecified Malware Jul17 2C 2017-07-19 10:17:25 -06:00
Florian Roth
2ee1f0fae8 LSASS Dump only if not filename starts with WER 2017-07-19 10:17:00 -06:00
Florian Roth
9146e905b3 Identified unspecified malware as Sality 2017-07-19 10:16:32 -06:00
Florian Roth
4423c86255 New filename IOCs 2017-07-19 10:14:56 -06:00
wesdawg
e657e23aed Remove chickenkiller domain string
chickenkiller is dynamic DNS, not WildNeutron specific.
2017-07-18 16:46:58 -04:00
Florian Roth
ccac0893d8 Disclosed Disclosed 0day POC set 2017-07-13 08:36:43 -06:00
Florian Roth
f55f9b5205 NCCGroups WinPayloads 2017-07-13 08:02:20 -06:00
Florian Roth
5141f48e15 Updated File Type Signatures 2017-07-13 08:01:57 -06:00
Florian Roth
2b8f5e9249 False Positive Reduction 2017-07-13 08:00:52 -06:00
Florian Roth
90499b61d7 PAS Webshell 2017-07-11 13:38:38 -06:00