Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule AgentTesla_mod_tough_bin
- {
- meta:
- author = "James_inthe_box"
- reference = "https://app.any.run/tasks/3b5d409c-978b-4a95-a5f1-399f0216873d/"
- date = "2019/11"
- maltype = "RAT"
- strings:
- $stringset31 = "OperatingSystemName"
- $stringset32 = "ProcessorName"
- $stringset33 = "AmountOfMemory"
- $stringset34 = "VideocardName"
- $stringset35 = "VideocardMem"
- $stringset36 = "Password"
- $stringset37 = "Mozilla"
- $stringset38 = "Postbox"
- $stringset39 = "Thunderbird"
- $stringset311 = "SeaMonkey"
- $stringset312 = "Flock"
- $stringset313 = "BlackHawk"
- $stringset314 = "CyberFox"
- $stringset315 = "KMeleon"
- $stringset316 = "IceCat"
- $stringset317 = "PaleMoon"
- $stringset318 = "IceDragon"
- $stringset319 = "WaterFox"
- condition:
- 10 of ($stringset3*)
- }
- rule AgentTesla_mod_tough_mem
- {
- meta:
- author = "James_inthe_box"
- reference = "https://app.any.run/tasks/3b5d409c-978b-4a95-a5f1-399f0216873d/"
- date = "2019/11"
- maltype = "RAT"
- strings:
- $string1 = "Opera Software\\Opera Stable" wide ascii
- $string2 = "keychain.plist" wide ascii
- $stringset1 = "type={0}" ascii wide
- $stringset2 = "hwid={1}" ascii wide
- $stringset3 = "time={2}" ascii wide
- $stringset4 = "pcname={3}" ascii wide
- $stringset5 = "logdata={4}" ascii wide
- $stringset6 = "screen={5}" ascii wide
- $stringset7 = "ipadd={6}" ascii wide
- $stringset8 = "webcam_link={7}" ascii wide
- $stringset9 = "screen_link={8}" ascii wide
- $stringset10 = "[passwords]" ascii wide
- condition:
- all of ($string*) and 5 of ($stringset*)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement