Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /*
- Yara Rule Set
- Author: Ialle Teixeira
- Date: 2017-06-27
- Identifier: Petya
- */
- /* Rule Set ----------------------------------------------------------------- */
- rule Petya_MalwareverseBrasil {
- meta:
- description = "Samples encontrados dia 27/06 by Malwareverse Brasil"
- author = "Ialle Teixeira"
- hash1 = "027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745"
- hash2 = "64b0b58a2c030c77fdb2b537b2fcc4af432bc55ffb36599a31d418c7c69e94b1"
- hash3 = "752e5cf9e47509ce51382c88fc4d7e53b5ca44ba22a94063f95222634b362ca5"
- hash4 = "027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745"
- strings:
- $x1 = "Ooops, your important files are encrypted." fullword wide
- $x2 = "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\%s\\\" #1 " fullword wide
- $x3 = "-d C:\\Windows\\System32\\rundll32.exe \"C:\\Windows\\%s\",#1 " fullword wide
- $x4 = "Send your Bitcoin wallet ID and personal installation key to e-mail " fullword wide
- $x5 = "fsutil usn deletejournal /D %c:" fullword wide
- $x6 = "wevtutil cl Setup & wevtutil cl System"
- $s1 = "%s /node:\"%ws\" /user:\"%ws\" /password:\"%ws\" " fullword wide
- $s2 = "\\\\.\\pipe\\%ws" fullword wide
- $s3 = "schtasks %ws/Create /SC once /TN \"\" /TR \"%ws\" /ST %02d:%02d" fullword wide
- $s4 = "u%s \\\\%s -accepteula -s " fullword wide
- $s5 = "dllhost.dat" fullword wide
- $s6 = "get_CurrentThread" fullword nocase wide ascii
- condition:
- uint16(0) == 0x5a4d and filesize < 1000KB and ( 1 of ($x*) or 3 of them )
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement