Advertisement
PepperPotts

share 02/2019 yara rule

Apr 27th, 2019
352
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.01 KB | None | 0 0
  1. rule shade_02_2019 {
  2. strings:
  3. $s1="\\torrc-defaults"
  4. $s2="@mail.ru"
  5. $s3=",\"data\":\""
  6. $s4="\"index\":"
  7. $s5="\"block\":"
  8. $s6="\"base\":"
  9. $s7=",\"found\":["
  10. $s8="{\"type\":1,\"report\":{\"id\":"
  11. $s9="s.com/ip/"
  12. $s10="mail,smtp,mailgate,relay"
  13. $s11="http://www.anti-abuse.org/multi-rbl-check-results/?host="
  14. $s12="http://whatismyipaddress.com/"
  15. $s13="//whatismyipaddress.com/ip/"
  16. $s14="http://whatsmyip.net/"
  17. $s15="WindowsSessionManager.lnk"
  18. $s16="/reg.php?"
  19. $s17="hW[] = "
  20. $s18="upd.php?"
  21. $s19="/task.php?"
  22. $s20="/rep.php"
  23. $s21="/ip.php"
  24. $s22="nocache="
  25. $s23="!update"
  26. $s24="!sleep"
  27. $s25="!reg"
  28. $s26="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\"
  29. $s27="--ignore-missing-torrc"
  30. $s28=".onion"
  31. $s29="csrss.exe"
  32. $s30="services"
  33. condition:
  34. (17 of them)
  35. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement