Giter Site home page Giter Site logo

yara-rules's Introduction

Yara-Rules

Repository of YARA rules to accompany the Trellix ATR blogposts & investigations

We endorse contributing to improve our rules - please send us a pull request with your proposal

In case you discovered a false positive with our rules, please share with us your details in an issue report and we’ll try to improve our Yara rules.

Happy Hunting!

yara-rules's People

Contributors

3vangel1st avatar fr0gger avatar freyjamcafee avatar johntje avatar mavjs avatar mlodic avatar neo23x0 avatar ronbarrey avatar seifreed avatar sisoma2 avatar thisislibra avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

yara-rules's Issues

Some errors

FYI:

/opt/yararules/Yara-Rules/ransomware/RANSOM_RobbinHood.yar(2): error: syntax error, unexpected identifier, expecting '{'
/opt/yararules/Yara-Rules/ransomware/RANSOM_SamSam.yar(50): error: undefined identifier "pe"
/opt/yararules/Yara-Rules/ransomware/RANSOM_SamSam.yar(98): error: undefined identifier "pe"
/opt/yararules/Yara-Rules/ransomware/RANSOM_acroware.yar(0): error: syntax error, unexpected end of file, expecting '}'
/opt/yararules/Yara-Rules/ransomware/RANSOM_GPGQwerty.yar(8): error: syntax error, unexpected ':', expecting '='
/opt/yararules/Yara-Rules/ransomware/RANSOM_Magniber.yar(3): error: non-ascii character
/opt/yararules/Yara-Rules/ransomware/RANSOM_Magniber.yar(3): error: syntax error, unexpected end of file, expecting <condition>

RANSOM_Darkside.yar vs RANSOM_darkside.yar

Hello,

I just spotted that you have two rulesets for the same family RANSOM_Darkside.yar and RANSOM_darkside.yar. However, this file naming causes issues on systems with case-insensitive file systems, such as Windows. As a results, your repository cannot be properly cloned, etc. Consider unifying these two in one ruleset.

Thank you

A few android rule issues

FYI:

/opt/yararules/Yara-Rules/mobile/MOBILE_pwndroid5_downloader.yar(1): error: unknown module "androguard"
/opt/yararules/Yara-Rules/mobile/MOBILE_pwndroid5_downloader.yar(16): error: invalid field name "activity"
/opt/yararules/Yara-Rules/mobile/MOBILE_pwndroid5_downloader.yar(55): error: invalid field name "activity"

UUID meta

Could you add UUID in the Yara-Rules ? I would like to import those in CyCAT and having a unique reference would help a lot.

Trellix (FireEye) False Positive on VirusTotal.com

I am a developer in the RINA Tech UK software team who authored a file which has been reported as "Gen:Variant.Lazy.398487" on virustotal.com by the Trellix (FireEye) engine, when 82% of anti-virus engines did not detect any issues. I believe the Trellix (FireEye) results to be a false positive.

I have uploaded it to a cloud storage service provided by my company:
https://depot.rina.org/access/kWvx5atetqkys4qoS5DWfMY2ch5n
[The password for the uploaded file is “infected” (without the double quotes)]

If you'd like any further information, please let me know.

Many thanks,
Clive

Some fixes

FYI:

/opt/yararules/Yara-Rules/APT/APT_hikit_rootkit_pdb.yar(8): error: syntax error, unexpected text string, expecting '='
/opt/yararules/Yara-Rules/APT/ixeshe_bled_pdb.yar(7): error: syntax error, unexpected text string, expecting '='
/opt/yararules/Yara-Rules/APT/APT_milum_wildpressure.yar(20): error: undefined identifier "pe"

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.