Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /* Rule Set ----------------------------------------------------------------- */
- import "pe"
- rule artifact_sample {
- meta:
- description = "sample.exe"
- author = "V"
- hash1 = "bdf36127817413f625d2625d3133760af724d6ad2410bea7297ddc116abc268f"
- strings:
- $x1 = ".?AV?$clone_impl@U?$error_info_injector@Vtask_already_started@boost@@@exception_detail@boost@@@exception_detail@boost@@" fullword ascii
- $s2 = ".?AV?$clone_impl@U?$error_info_injector@Vtask_moved@boost@@@exception_detail@boost@@@exception_detail@boost@@" fullword ascii
- $s3 = ".?AU?$error_info_injector@Vtask_already_started@boost@@@exception_detail@boost@@" fullword ascii
- $s4 = "Attempts to restore your data with third party software as Photorec, RannohDecryptor etc." fullword wide
- $s5 = "E:\\crypto-locker\\tpls_MSVC\\include\\boost-1_68\\boost/thread/concurrent_queues/detail/sync_queue_base.hpp" fullword ascii
- $s6 = ".?AU?$error_info_injector@Usync_queue_is_closed@concurrent@boost@@@exception_detail@boost@@" fullword ascii
- $s7 = ".?AU?$error_info_injector@Vtask_moved@boost@@@exception_detail@boost@@" fullword ascii
- $s8 = ".?AV?$clone_impl@U?$error_info_injector@Vinvalid_command_line_syntax@program_options@boost@@@exception_detail@boost@@@exception_" ascii
- $s9 = ".?AU?$basic_pipebuf@_WU?$char_traits@_W@std@@@process@boost@@" fullword ascii
- $s10 = ".?AU?$task_shared_state@V?$_Binder@U_Unforced@std@@AAV<lambda_8a7570b976bc101d83292d43f9603e9c>@@HI@std@@X@detail@boost@@" fullword ascii
- $s11 = "E:\\crypto-locker\\tpls_MSVC\\include\\boost-1_68\\boost/exception/detail/exception_ptr.hpp" fullword ascii
- $s12 = "You should be thankful that the flaw was exploited by serious people and not some rookies." fullword wide
- $s13 = ".?AUprocess_error@process@boost@@" fullword ascii
- $s14 = ".?AV?$basic_ipstream@_WU?$char_traits@_W@std@@@process@boost@@" fullword ascii
- $s15 = ".?AVwindows_file_codecvt@windows@detail@process@boost@@" fullword ascii
- $s16 = ".?AV?$ModePolicyCommonTemplate@UAdditiveCipherAbstractPolicy@CryptoPP@@@CryptoPP@@" fullword ascii
- $s17 = "CreateProcess failed" fullword ascii
- $s18 = "CottleAkela@protonmail.com;QyavauZehyco1994@o2.pl" fullword wide
- $s19 = "E:\\crypto-locker\\cryptopp\\src\\rijndael_simd.cpp" fullword ascii
- $s20 = "As soon as we receive the payment you will get the decryption tool and" fullword wide
- condition:
- uint16(0) == 0x5a4d and filesize < 4000KB and
- ( pe.imphash() == "c226ac4bab6f48634bacbb7a1d34f8f6" or ( 1 of ($x*) or 4 of them ) )
- }
- ~
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement