Advertisement
Guest User

Yara rules for Hola

a guest
Jun 3rd, 2015
326
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
YAML 1.14 KB | None | 0 0
  1. rule Zon_Network {
  2.     meta:
  3.         description = "ZON Networks protocol"
  4.         thread_level = 3
  5.         in_the_wild = true
  6.         authors = "Vectra"
  7.         date = "5-10-15"
  8.        
  9.     strings:
  10.         $s1 = "zconn_new"
  11.         $s2 = "zmsg_znatconnect_handler"
  12.         $s3 = "zmsg_upgrade"
  13.         $s4 = "zmsg_snd_rcv_handler"
  14.         $s5 = "zmsg_upgrade_peer"
  15.         $s6 = "zmsg_ts_long_cb"
  16.         $s7 = "zmsg_write"
  17.         $s8 = "zmsg_http_write"
  18.         $s9 = "zmsg_http_read"
  19.         $s10 = "zmsg_write_handler"
  20.         $s11 = "zmsg_read"
  21.         $s12 = "zmsg_read received"
  22.         $s13 = "zmsg_read_handler"
  23.         $s14 = "zmsg_read_invalid"
  24.         $s15 = "zmsg_magic_write_handler"
  25.         $s16 = "zmsg_magic_read_handler"
  26.         $s17 = "zmsg_http_send_handler"
  27.         $s18 = "zmsg_zping_resp_handler"
  28.         $s19 = "zmsg_route_req_handler"
  29.         $s20 = "zmsg_route_get_next_hop_cb"
  30.         $s21 = "zconn_son_free"
  31.         $s22 = "zconn_write_handler"
  32.         $s23 = "zconn_read_handler"
  33.         $s24 = "zconn_write"
  34.         $s25 = "zconn_read"
  35.         $s26 = "zconn_dns_fail"
  36.         $s27 = "zconn_http_handler"
  37.         $s28 = "zconn_local_handler"
  38.         $s29 = "zconn_handler"
  39.         $s30 = "zmsg_release"
  40.         $s31 = "zmsg_fail_connect"
  41.         $s32 = "zmsg_accumulate"
  42.         $s33 = "zconn_info"
  43.     condition:
  44.         10 of them
  45. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement