Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule Gh0st_Cringe_bin
- {
- meta:
- description = "Gh0st-Cringe RAT"
- author = "James_inthe_box"
- reference = "62f02dd911ed52ffa87d1c8215199bfad471a7d5d0ef905eb16f45b0bb49ed94"
- date = "2019/05"
- maltype = "RAT"
- strings:
- $string1 = "PluginMe"
- $string2 = "%d.bak"
- $string3 = "System"
- $string4 = "Security"
- $string5 = "Application"
- $string6 = "Group"
- $string7 = "Remark"
- $string8 = "HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"
- $secapp9 = "UnThreat"
- $secapp10 = "UnThreat.exe"
- $secapp11 = "K7TSecurity.exe"
- $secapp12 = "Ad-watch"
- $secapp13 = "ad-watch.exe"
- $secapp14 = "PSafe"
- $secapp15 = "PSafeSysTray.exe"
- $secapp16 = "BitDefender"
- $secapp17 = "vsserv.exe"
- $secapp18 = "remupd.exe"
- $secapp19 = "rtvscan.exe"
- $secapp20 = "Avast"
- $secapp21 = "ashDisp.exe"
- $secapp22 = "avcenter.exe"
- $secapp23 = "TMBMSRV.exe"
- $secapp24 = "knsdtray.exe"
- $secapp25 = "NOD32"
- $secapp26 = "egui.exe"
- $secapp27 = "Mcshield.exe"
- $secapp28 = "avp.exe"
- $secapp29 = "F-Secure"
- $secapp30 = "f-secure.exe"
- $secapp31 = "avgwdsvc.exe"
- $secapp32 = "AYAgent.aye"
- $secapp33 = "V3Svc.exe"
- $secapp34 = "Outpost"
- $secapp35 = "acs.exe"
- $secapp36 = "DR.WEB"
- $secapp37 = "SPIDer.exe"
- $secapp38 = "Comodo"
- $secapp39 = "cfp.exe"
- $secapp40 = "mssecess.exe"
- $secapp41 = "QuickHeal"
- $secapp42 = "QUHLPSVC.EXE"
- $secapp43 = "RavMonD.exe"
- $secapp44 = "KvMonXP.exe"
- $secapp46 = "baiduSafeTray.exe"
- $secapp47 = "BaiduSd.exe"
- $secapp48 = "QQPCRTP.exe"
- $secapp49 = "KSafeTray.exe"
- $secapp50 = "kxetray.exe"
- $secapp51 = "360sd.exe"
- $secapp52 = "360tray.exe"
- $secapp53 = "MSIE 6.0"
- condition:
- uint16(0) == 0x5A4D and 7 of ($string*) and 20 of ($secapp*) and filesize < 100KB
- }
- rule Gh0st_Cringe_mem
- {
- meta:
- description = "Gh0st-Cringe RAT"
- author = "James_inthe_box"
- reference = "62f02dd911ed52ffa87d1c8215199bfad471a7d5d0ef905eb16f45b0bb49ed94"
- date = "2019/05"
- maltype = "RAT"
- strings:
- $string1 = "PluginMe"
- $string2 = "%d.bak"
- $string3 = "System"
- $string4 = "Security"
- $string5 = "Application"
- $string6 = "Group"
- $string7 = "Remark"
- $string8 = "HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"
- $secapp9 = "UnThreat"
- $secapp10 = "UnThreat.exe"
- $secapp11 = "K7TSecurity.exe"
- $secapp12 = "Ad-watch"
- $secapp13 = "ad-watch.exe"
- $secapp14 = "PSafe"
- $secapp15 = "PSafeSysTray.exe"
- $secapp16 = "BitDefender"
- $secapp17 = "vsserv.exe"
- $secapp18 = "remupd.exe"
- $secapp19 = "rtvscan.exe"
- $secapp20 = "Avast"
- $secapp21 = "ashDisp.exe"
- $secapp22 = "avcenter.exe"
- $secapp23 = "TMBMSRV.exe"
- $secapp24 = "knsdtray.exe"
- $secapp25 = "NOD32"
- $secapp26 = "egui.exe"
- $secapp27 = "Mcshield.exe"
- $secapp28 = "avp.exe"
- $secapp29 = "F-Secure"
- $secapp30 = "f-secure.exe"
- $secapp31 = "avgwdsvc.exe"
- $secapp32 = "AYAgent.aye"
- $secapp33 = "V3Svc.exe"
- $secapp34 = "Outpost"
- $secapp35 = "acs.exe"
- $secapp36 = "DR.WEB"
- $secapp37 = "SPIDer.exe"
- $secapp38 = "Comodo"
- $secapp39 = "cfp.exe"
- $secapp40 = "mssecess.exe"
- $secapp41 = "QuickHeal"
- $secapp42 = "QUHLPSVC.EXE"
- $secapp43 = "RavMonD.exe"
- $secapp44 = "KvMonXP.exe"
- $secapp46 = "baiduSafeTray.exe"
- $secapp47 = "BaiduSd.exe"
- $secapp48 = "QQPCRTP.exe"
- $secapp49 = "KSafeTray.exe"
- $secapp50 = "kxetray.exe"
- $secapp51 = "360sd.exe"
- $secapp52 = "360tray.exe"
- $secapp53 = "MSIE 6.0"
- condition:
- 7 of ($string*) and 20 of ($secapp*) and filesize > 100KB
- }
Advertisement
Add Comment
Please, Sign In to add comment