Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Community Scans b350eae6c630a1d2340703a6...

Community Scan Report

Flagged

b350eae6c630a1d2340703a6d01a6031b2c98941b50bd826732fca4ca792da24

Detection Ratio

53 / 4097 rules matched

146840 ms scan time
53 rules matched

Matches rule APT17_Sample_FXSST_DLL from malware

Detects Samples related to APT17 activity - file FXSST.DLL

Matched Strings

$s2
Offset (hex) Offset (dec) Length Matched Data
0x3AFAD0 3865296 5 Sleep
0x4192EE 4297454 5 Sleep
0x4192F6 4297462 5 Sleep
0x8EB2F9 9351929 5 Sleep
0x9ADBD5 10148821 5 Sleep
0x9ADBDD 10148829 5 Sleep
0x9ADBF9 10148857 5 Sleep
rule APT17_Sample_FXSST_DLL
{Roth
	Date: 2015-05-14
	Identifier: APT17
*/

/* Rule Set ----------------------------------------------------------------- */

rule APT17_Sample_FXSST_DLL {
	meta:
		description = "Detects Samples related to APT17 activity - file FXSST.DLL"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://goo.gl/ZiJyQv"
		date = "2015-05-14"
		hash = "52f1add5ad28dc30f68afda5d41b354533d8bce3"
		id = "e4b9b25e-8895-5ba5-b706-bfb6892c16ae"
	strings:
		$x1 = "Microsoft? Windows? Operating System" fullword wide
		$x2 = "fxsst.dll" fullword ascii

		$y1 = "DllRegisterServer" fullword ascii
		$y2 = ".cSV" fullword ascii

		$s1 = "GetLastActivePopup"
		$s2 = "Sleep"
		$s3 = }

Matches rule APT28_CHOPSTICK from malware

Detects a malware that behaves like CHOPSTICK mentioned in APT28 report

Matched Strings

$s8
Offset (hex) Offset (dec) Length Matched Data
0x41997B 4299131 12 KERNEL32.dll
0x9AE418 10150936 12 KERNEL32.dll
$s9
Offset (hex) Offset (dec) Length Matched Data
0x418DF6 4296182 17 IsDebuggerPresent
0x9AD63B 10147387 17 IsDebuggerPresent
rule APT28_CHOPSTICK
{arGen Rule Generator
	Date: 2015-06-02
	Identifier: APT28
*/

/* Rule Set ----------------------------------------------------------------- */

rule APT28_CHOPSTICK {
	meta:
		description = "Detects a malware that behaves like CHOPSTICK mentioned in APT28 report"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://goo.gl/v3ebal"
		date = "2015-06-02"
		hash = "f4db2e0881f83f6a2387ecf446fcb4a4c9f99808"
		score = 60
		id = "08bc4cc2-1844-5218-bb89-20a3ac70a951"
	strings:
		$s0 = "jhuhugit.tmp" fullword ascii /* score: '14.005' */
		$s8 = "KERNEL32.dll" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 14405 times */
		$s9 = "IsDebuggerPresent" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' }

Matches rule APT_CN_TwistedPanda_SPINNER_1

12×

Matched Strings

$config_init
Offset (hex) Offset (dec) Length Matched Data
0x18E126 1630502 15 \xC7A\x08\x00\x00\x00\x00\xC7A\x0C\x00\x00\x00\x00\xC6
0x1FD06E 2084974 15 \xC7F(\x00\x00\x00\x00\xC7F,\x00\x00\x00\x00\xC6
0x201DC0 2104768 15 \xC7F\x0C\x00\x00\x00\x00\xC7F\x10\x00\x00\x00\x00\xC6
0x635C17 6511639 15 \xC7A\x08\x00\x00\x00\x00\xC7A\x0C\x00\x00\x00\x00\xC6
0x6A6EEF 6975215 15 \xC7F(\x00\x00\x00\x00\xC7F,\x00\x00\x00\x00\xC6
0x6ABC41 6995009 15 \xC7F\x0C\x00\x00\x00\x00\xC7F\x10\x00\x00\x00\x00\xC6
$c2_cmd_2
Offset (hex) Offset (dec) Length Matched Data
0x3DB96C 4045164 4 \x02\x00\x01\x10
0x3DB978 4045176 4 \x02\x00\x01\x10
0x3DB984 4045188 4 \x02\x00\x01\x10
0x9461ED 9724397 4 \x02\x00\x01\x10
0x9461F9 9724409 4 \x02\x00\x01\x10
0x946205 9724421 4 \x02\x00\x01\x10

Matches rule APT_DarkHydrus_Jul18_3 from malware

Detects strings found in malware samples in APT report in DarkHydrus

Matched Strings

$s9
Offset (hex) Offset (dec) Length Matched Data
0x3B742D 3896365 6 StartW
0x3C178B 3938187 6 StartW
0x8EA4A2 9348258 6 StartW
0x8FCB5C 9423708 6 StartW
rule APT_DarkHydrus_Jul18_3
{Roth (Nextron Systems)"
      reference = "https://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/"
      date = "2018-07-28"
      hash1 = "b2571e3b4afbce56da8faa726b726eb465f2e5e5ed74cf3b172b5dd80460ad81"
      id = "1a21cbbf-f7e1-56eb-973b-35c1a811e210"
   strings:
      $s4 = "windir" fullword ascii /* Goodware String - occured 47 times */
      $s6 = "temp.dll" fullword ascii /* Goodware String - occured 3 times */
      $s7 = "libgcj-12.dll" fullword ascii /* Goodware String - occured 3 times */
      $s8 = "%s\\System32\\%s" fullword ascii /* Goodware String - occured 4 times */
      $s9 = "StartW" fullwo}

Matches rule APT_DonotTeam_YTYframework from malware by James E.C, ProofPoint

Modular malware framework with similarities to EHDevel

APT
DonotTeam
Windows
AuthorJames E.C, ProofPoint

Matched Strings

$s9
Offset (hex) Offset (dec) Length Matched Data
0x3C27AA 3942314 22 d\x00b\x00g\x00h\x00e\x00l\x00p\x00.\x00d\x00l\x00l\x00
0x8FDBCB 9427915 22 d\x00b\x00g\x00h\x00e\x00l\x00p\x00.\x00d\x00l\x00l\x00
rule APT_DonotTeam_YTYframework : APT DonotTeam Windows
{
   meta:
      author = "James E.C, ProofPoint"
      description = "Modular malware framework with similarities to EHDevel"
      hashes = "1e0c1b97925e1ed90562d2c68971e038d8506b354dd6c1d2bcc252d2a48bc31c"
      reference = "https://www.arbornetworks.com/blog/asert/donot-team-leverages-new-modular-malware-framework-south-asia/"
      reference2 = "https://labs.bitdefender.com/2017/09/ehdevel-the-story-of-a-continuously-improving-advanced-threat-creation-toolkit/"
      date = "08-03-2018"
      id = "6dd07019-aa5a-5966-8331-b6f6758b0652"
   strings:
      $x1 = "/football/download2/" ascii wide
      $x2 = "/football/download/" ascii wide
      $x3 = "Caption: Xp>" wide

      $x_c2 = "5.135.199.0" ascii fullword

      $a1 = "getGoogle" ascii fullword
      $a2 = "/q /noretstart" wide
      $a3 = "IsInSandbox" ascii fullword
      $a4 = "syssystemnew" ascii fullword
      $a5 = "ytyinfo" ascii fullword
      $a6 = "\\ytyboth\\yty " ascii

      $s1 = "SELECT Name FROM Win32_Processor" wide
      $s2 = "SELECT Caption FROM Win32_OperatingSystem" wide
      $s3 = "SELECT SerialNumber FROM Win32_DiskDrive" wide
      $s4 = "VM: Yes" wide fullword
      $s5 = "VM: No" wide fullword
      $s6 = "helpdll.dll" ascii fullword
      $s7 = "boothelp.exe" ascii fullword
      $s8 = "SbieDll.dll" wide fullword
      $s9 = "dbghelp.dll" wide fullword
      $s10 = "YesNoMaybe" ascii fullword
      $s11 = "saveData" ascii fullword
      $s12 = "saveLo}

Matches rule APT_Loader_Win32_DShell_3 from malware by FireEye

AuthorFireEye

Matched Strings

$ss1
Offset (hex) Offset (dec) Length Matched Data
0x97231E 9904926 14 \x00CreateThread\x00
rule APT_Loader_Win32_DShell_3
{You may not use this file except in compliance with the license. The license should have been received with this file. You may obtain a copy of the license at:
// https://github.com/fireeye/red_team_tool_countermeasures/blob/master/LICENSE.txt
rule APT_Loader_Win32_DShell_3
{
    meta:
        date_created = "2020-11-27"
        date_modified = "2020-11-27"
        md5 = "12c3566761495b8353f67298f15b882c"
        rev = 1
        author = "FireEye"
    strings:
        $sb1 = { 6A 40 68 00 30 00 00 [4-32] E8 [4-8] 50 [0-16] E8 [4-150] 6A FF [1-32] 6A 00 6A 00 5? 6A 00 6A 00 [0-}

Matches rule APT_Loader_Win64_PGF_1 from malware by FireEye

base dlls: /lib/payload/techniques/unmanaged_exports/

50×
AuthorFireEye

Matched Strings

$sb1
50×
Offset (hex) Offset (dec) Length Matched Data
0xF34 3892 1 \xB9
0xF7D 3965 1 \xB9
0xF96 3990 1 \xB9
0x10BC 4284 1 \xB9
0x1150 4432 1 \xB9
0x17CB 6091 1 \xB9
0x2056 8278 1 \xB9
0xD185 53637 1 \xB9
0xD2E0 53984 1 \xB9
0xE26B 57963 1 \xB9
0xE508 58632 1 \xB9
0xE590 58768 1 \xB9
0xE645 58949 1 \xB9
0xE737 59191 1 \xB9
0xE8A4 59556 1 \xB9
0xE96D 59757 1 \xB9
0xE98F 59791 1 \xB9
0xE9F8 59896 1 \xB9
0xEA20 59936 1 \xB9
0xEAB2 60082 1 \xB9
0xECC7 60615 1 \xB9
0xECE3 60643 1 \xB9
0xECF6 60662 1 \xB9
0x10912 67858 1 \xB9
0x10940 67904 1 \xB9
0x10956 67926 1 \xB9
0x10A10 68112 1 \xB9
0x10AEC 68332 1 \xB9
0x11B1A 72474 1 \xB9
0x11C3B 72763 1 \xB9
0x12180 74112 1 \xB9
0x121A4 74148 1 \xB9
0x12D88 77192 1 \xB9
0x12DAC 77228 1 \xB9
0x1361E 79390 1 \xB9
0x13641 79425 1 \xB9
0x16ABD 92861 1 \xB9
0x17154 94548 1 \xB9
0x17251 94801 1 \xB9
0x17549 95561 1 \xB9
0x176F0 95984 1 \xB9
0x178D1 96465 1 \xB9
0x17E21 97825 1 \xB9
0x18855 100437 1 \xB9
0x1916C 102764 1 \xB9
0x19330 103216 1 \xB9
0x1933B 103227 1 \xB9
0x1939F 103327 1 \xB9
0x193A7 103335 1 \xB9
0x19DE6 105958 1 \xB9
rule APT_Loader_Win64_PGF_1
{00 00 FF D0 89 44 24 ?? C7 04 24 08 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? 83 7D ?? 00 75 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 E9 ?? ?? ?? ?? C7 45 ?? 00 00 00 00 C7 45 ?? 00 00 00 00 C7 85 ?? ?? ?? ?? 28 04 00 00 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 85 ?? ?? ?? ?? 02 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? 83 7D ?? 00 74 ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? 00 00 00 00 8D 95 ?? ?? ?? ?? 83 C2 20 89 14 24 89 C1 E8 ?? ?? ?? ?? 83 EC 08 83 F8 FF 0F 95 C0 84 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 85 ?? ?? ?? ?? 02 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? EB ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 04 83 7D ?? 00 74 ?? 83 7D ?? 00 75 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 E9 ?? ?? ?? ?? C7 04 24 7E 40 D9 63 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 04 C7 44 24 ?? 8A 40 D9 63 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC 08 89 45 ?? 89 E8 89 45 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC 08 C7 45 ?? 00 00 00 00 8B 55 ?? 8B 85 ?? ?? ?? ?? 39 C2 0F 83 ?? ?? ?? ?? 8B 45 ?? 8B 00 3D FF 0F 00 00 0F 86 ?? ?? ?? ?? 8B 45 ?? 8B 00 39 45 ?? 73 ?? 8B 45 ?? 8B 00 8B 55 ?? 81 C2 00 10 00 00 39 D0 73 ?? C7 45 ?? 01 00 00 00 83 7D ?? 00 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 00 39 45 ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? 8B 00 8B 4D ?? 8B 55 ?? 01 CA 39 D0 0F 83 ?? ?? ?? ?? B9 00 00 00 00 B8 1C 00 00 00 83 E0 FC 89 C2 B8 00 00 00 00 89 8C 05 ?? ?? ?? ?? 83 C0 04 39 D0 72 ?? 8B 45 ?? 8B 00 C7 44 24 ?? 1C 00 00 00 8D 95 ?? ?? ?? ?? 89 54 24 ?? 89 04 24 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 0C 8B 85 ?? ?? ?? ?? 83 E0 20 85 C0 74 ?? 8B 45 ?? 8B 00 C7 44 24 ?? 30 14 D4 63 }

Matches rule APT_Loader_Win64_PGF_4 from malware by FireEye

AuthorFireEye

Matched Strings

$e1
Offset (hex) Offset (dec) Length Matched Data
0x4267E4 4351972 3 ,1,
$e3
Offset (hex) Offset (dec) Length Matched Data
0x3D7E99 4030105 3 ,3,
0x94271A 9709338 3 ,3,
$e7
Offset (hex) Offset (dec) Length Matched Data
0x3D7E9B 4030107 3 ,7,
0x94271C 9709340 3 ,7,
rule APT_Loader_Win64_PGF_4
{-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html"
        author = "FireEye"
        id = "31717164-9876-58f8-af27-d27c81d20fba"
    strings:
        $dlang1 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\utf.d" ascii wide
        $dlang2 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\file.d" ascii wide
        $dlang3 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\format.d" ascii wide
        $dlang4 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\base64.d" ascii wide
        $dlang5 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\stdio.d" ascii wide
        $dlang6 = "\\..\\..\\src\\phobos\\std\\utf.d" ascii wide
        $dlang7 = "\\..\\..\\src\\phobos\\std\\file.d" ascii wide
        $dlang8 = "\\..\\..\\src\\phobos\\std\\format.d" ascii wide
        $dlang9 = "\\..\\..\\src\\phobos\\std\\base64.d" ascii wide
        $dlang10 = "\\..\\..\\src\\phobos\\std\\stdio.d" ascii wide
        $dlang11 = "Unexpected '\\n' when converting from type const(char)[] to type int" ascii wide
        $e0 = ",0,"
        $e1 = ",1,"
        $e2 = ",2,"
        $e3 = ",3,"
        $e4 = ",4,"
        $e5 = ",5,"
        $e6 = ",6,"
        $e7 = ",7,"
        $e8 = ",8,"
        $e9 = ",9,"
        $e10 = ",10,"
        $e11 = ",11,"
        $e12 = ",12,"
        $e13 = ",13,"
        $e14 = ",14,"
        $e15 = ",15,"
        $e16 = ",16,"
        $e17 = ",17,"
        $e18 = ",18,"
        $e19 = ",19,"
        $e20 = ",20,"
        $e21 = ",21,"
        $e22 = ",22,"
        $e23 = ",23,"
        $e24 = ",24,"
        $e25 = ",25,"
        $e26 = ",26,"
        $e27 = ",27,"
        $e28 = ",28,"
 }

Matches rule APT_MAL_ASPX_HAFNIUM_Chopper_Mar21_3 from malware by Florian Roth (Nextron Systems)

Detects HAFNIUM ASPX files dropped on compromised servers

50×
AuthorFlorian Roth (Nextron Systems)

Matched Strings

$script1
Offset (hex) Offset (dec) Length Matched Data
0x990A38 10029624 15 script language
0x9923C8 10036168 15 script language
$script4
48×
Offset (hex) Offset (dec) Length Matched Data
0x8E8A3B 9341499 14 /\x00s\x00c\x00r\x00i\x00p\x00t\x00
0x902515 9446677 7 /Script
0x90402F 9453615 7 /Script
0x986782 9987970 7 /script
0x986DFE 9989630 7 /script
0x9879A4 9992612 7 /script
0x987A7E 9992830 7 /script
0x987C85 9993349 7 /script
0x988E14 9997844 7 /script
0x988F4C 9998156 7 /script
0x9891A4 9998756 7 /script
0x989654 9999956 7 /script
0x98A11B 10002715 7 /script
0x98A615 10003989 7 /script
0x98D2AF 10015407 7 /script
0x98D646 10016326 7 /script
0x98D718 10016536 7 /script
0x98DA53 10017363 7 /script
0x98DCE3 10018019 7 /script
0x98DFA0 10018720 7 /script
0x98E436 10019894 7 /script
0x98E8CD 10021069 7 /script
0x98ECA3 10022051 7 /script
0x98F2E1 10023649 7 /script
0x98F4FE 10024190 7 /script
0x98F60D 10024461 7 /script
0x98F9A9 10025385 7 /script
0x98FA43 10025539 7 /script
0x99006F 10027119 7 /script
0x9900E0 10027232 7 /script
0x9901F0 10027504 7 /script
0x99028E 10027662 7 /script
0x9904FF 10028287 7 /script
0x99051E 10028318 7 /script
0x99052F 10028335 7 /script
0x990884 10029188 7 /script
0x990A6C 10029676 7 /script
0x990D2D 10030381 7 /script
0x9914EB 10032363 7 /script
0x991A54 10033748 7 /script
0x99247B 10036347 7 /script
0x992660 10036832 7 /script
0x9929CB 10037707 7 /script
0x992C2F 10038319 7 /script
0x992E0B 10038795 7 /script
0x993000 10039296 7 /script
0x993104 10039556 7 /script
0x9942B6 10044086 7 /script
rule APT_MAL_ASPX_HAFNIUM_Chopper_Mar21_3
{geting-exchange-servers/"
      id = "27677f35-24a3-59cc-a3ad-b83884128da7"
   strings:
      $script1 = "script language" ascii wide nocase
      $script2 = "page language" ascii wide nocase
      $script3 = "runat=\"server\"" ascii wide nocase
      $script4 = "/script" ascii wide nocase
      $externalurl = "externalurl" ascii wide nocase
      $internalurl = "internalurl" ascii wide nocase
      $internalauthenticationmethods = "internalauthenticatio}

Matches rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3 from malware by Mandiant

Detects VEILEDSIGNAL malware

AuthorMandiant

Matched Strings

$si2
Offset (hex) Offset (dec) Length Matched Data
0x4184D2 4293842 16 CreateNamedPipeW
0x9ACC11 10144785 16 CreateNamedPipeW
$si3
Offset (hex) Offset (dec) Length Matched Data
0x418506 4293894 12 CreateThread
0x97231F 9904927 12 CreateThread
0x9ACC59 10144857 12 CreateThread
rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3
{BinaryToStringA" fullword
      $si2 = "BCryptGenerateSymmetricKey" fullword
      $si3 = "CreateThread" fullword
      $ss1 = "ChainingModeGCM" wide
      $ss2 = "__tutma" fullword
   condition:
      (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them
}

rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3 {
   meta:
      description = "Detects VEILEDSIGNAL malware"
      author = "Mandiant"
      score = 75
      disclaimer = "This rule is meant for hunting and is not tested to run in a production environment"
      md5 = "c6441c961dcad0fe127514a918eaabd4"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "82790c65-1d93-509b-95df-841543943c30"
   strings:
      $ss1 = { 61 70 70 6C 69 63 61 74 69 6F 6E 2F 6A 73 6F 6E 2C 20 74 65 78 74 2F 6A 61 76 61 73 63 72 69 70 74 2C 20 2A 2F 2A 3B 20 71 3D 30 2E 30 31 00 00 61 63 63 65 70 74 00 00 65 6E 2D 55 53 2C 65 6E 3B 71 3D 30 2E 39 00 00 61 63 63 65 70 74 2D 6C 61 6E 67 75 61 67 65 00 63 6F 6F 6B 69 65 00 00 }
      $si1 = "HttpSendRequestW" fullword
      $si2 = "CreateNamedPipeW" fullword
      $si3 = "CreateThread" fullword
      $se1 = "DllGetClassObject" fullword
   condition:
      (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them
}

rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_4 {
   meta:
      description = "Detects VEILEDSIGNAL malware"
      author = "Mandiant"
      score = 75
      disclaimer = "This rule is meant for hunting and is not tested to run in a production environment"
      hash1 = "404b09def6054a281b41d309d809a428" 
      hash2 = "c6441c961dcad0fe127514a918eaabd4"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "379e6471-3c4f-5c72-b8fd-17f481e89ac6"
   strings:
      $sb1 = { FF 15 FC 76 01 00 8B F0 85 C0 74 ?? 8D }

Matches rule APT_NK_TradingTech_ForensicArtifacts_Apr23_1 from malware by Florian Roth

Detects forensic artifacts, file names and keywords related the Trading Technologies compromise UNC4736

AuthorFlorian Roth

Matched Strings

$hex_uni4
Offset (hex) Offset (dec) Length Matched Data
0x8E6FC9 9334729 11 n\x00a\x00m\x00e\x00=\x00"
rule APT_NK_TradingTech_ForensicArtifacts_Apr23_1
{d to run in a production environment"
      description = "Detects strings found in POOLRAT malware"
      hash1 = "451c23709ecd5a8461ad060f6346930c"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "70f5f3a0-0fd0-54dc-97cc-4f3c35f02fcd"
   strings:
      /*
      $hex1 = { 6e 61 6d 65 3d 22 75 69 64 22 25 73 25 73 25 75 25 73 }
      $hex_uni1 = { 6e 00 61 00 6d 00 65 00 3d 00 22 00 75 00 69 00 64 00 22 00 25 00 73 00 25 00 73 00 25 00 75 00 25 00 73 }
      */
      $s1 = "name=\"uid\"%s%s%u%s" ascii wide
      /*
      $hex2 = { 6e 61 6d 65 3d 22 73 65 73 73 69 6f 6e 22 25 73 25 73 25 75 25 73 }
      $hex_uni2 = { 6e 00 61 00 6d 00 65 00 3d 00 22 00 73 00 65 00 73 00 73 00 69 00 6f 00 6e 00 22 00 25 00 73 00 25 00 73 00 25 00 75 00 25 00 73 }
      */
      $s2 = "name=\"session\"%s%s%u%s" ascii wide
      /*
      $hex3 = { 6e 61 6d 65 3d 22 61 63 74 69 6f 6e 22 25 73 25 73 25 73 25 73 }
      $hex_uni3 = { 6e 00 61 00 6d 00 65 00 3d 00 22 00 61 00 63 00 74 00 69 00 6f 00 6e 00 22 00 25 00 73 00 25 00 73 00 25 00 73 00 25 00 73 }
      */
      $s3 = "name=\"action\"%s%s%s%s" ascii wide
      /*
      $hex4 = { 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 25 73 25 73 25 75 25 73 }
      $hex_uni4 = { 6e 00 61 00 6d 00 65 00 3d 00 22 0}

Matches rule APT_Project_Sauron_Custom_M4 from malware by FLorian Roth

Detects malware from Project Sauron APT

50×
AuthorFLorian Roth

Matched Strings

$op0
50×
Offset (hex) Offset (dec) Length Matched Data
0x2C06D 180333 4 \x89M\xE8\x89
0x3AC03 240643 4 \x89M\xE8\x89
0x40962 264546 4 \x89M\xE8\x89
0x48C0F 297999 4 \x89M\xE8\x89
0x5508E 348302 4 \x89M\xE8\x89
0x57F4E 360270 4 \x89M\xE8\x89
0x896C8 562888 4 \x89M\xE8\x89
0x89B65 564069 4 \x89M\xE8\x89
0x89C69 564329 4 \x89M\xE8\x89
0x8B204 569860 4 \x89M\xE8\x89
0x8FA74 588404 4 \x89M\xE8\x89
0x91918 596248 4 \x89M\xE8\x89
0x924F2 599282 4 \x89M\xE8\x89
0x92549 599369 4 \x89M\xE8\x89
0x9AD1E 634142 4 \x89M\xE8\x89
0x9BAF7 637687 4 \x89M\xE8\x89
0xA1D3A 662842 4 \x89M\xE8\x89
0xA4226 672294 4 \x89M\xE8\x89
0xAD334 709428 4 \x89M\xE8\x89
0xB5827 743463 4 \x89M\xE8\x89
0xB58C5 743621 4 \x89M\xE8\x89
0xB5F19 745241 4 \x89M\xE8\x89
0xB9D42 761154 4 \x89M\xE8\x89
0xC2F60 798560 4 \x89M\xE8\x89
0xC303C 798780 4 \x89M\xE8\x89
0xD60A4 876708 4 \x89M\xE8\x89
0xD6663 878179 4 \x89M\xE8\x89
0xD9F0B 892683 4 \x89M\xE8\x89
0xDB2C4 897732 4 \x89M\xE8\x89
0xDBE9E 900766 4 \x89M\xE8\x89
0xDED9E 912798 4 \x89M\xE8\x89
0xE3734 931636 4 \x89M\xE8\x89
0xE50EF 938223 4 \x89M\xE8\x89
0xE823C 950844 4 \x89M\xE8\x89
0xEF8D1 981201 4 \x89M\xE8\x89
0xEFCB1 982193 4 \x89M\xE8\x89
0xF232B 992043 4 \x89M\xE8\x89
0xF9DD4 1023444 4 \x89M\xE8\x89
0x103AFF 1063679 4 \x89M\xE8\x89
0x1062FE 1073918 4 \x89M\xE8\x89
0x10E619 1107481 4 \x89M\xE8\x89
0x10E6B9 1107641 4 \x89M\xE8\x89
0x11752B 1144107 4 \x89M\xE8\x89
0x11B94B 1161547 4 \x89M\xE8\x89
0x120DD3 1183187 4 \x89M\xE8\x89
0x129D67 1219943 4 \x89M\xE8\x89
0x13448B 1262731 4 \x89M\xE8\x89
0x1730C9 1519817 4 \x89M\xE8\x89
0x174EFF 1527551 4 \x89M\xE8\x89
0x1775B7 1537463 4 \x89M\xE8\x89
rule APT_Project_Sauron_Custom_M4
{:
		( uint16(0) == 0x5a4d and filesize < 400KB and ( all of ($s*) ) and all of ($op*) )
}

rule APT_Project_Sauron_Custom_M3 {
	meta:
		description = "Detects malware from Project Sauron APT"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://goo.gl/eFoP4A"
		date = "2016-08-09"
		hash1 = "a4736de88e9208eb81b52f29bab9e7f328b90a86512bd0baadf4c519e948e5ec"
		id = "555b37a2-6a3c-539f-81dc-24c739795510"
	strings:
		$s1 = "ExampleProject.dll" fullword ascii

		$op0 = { 8b 4f 06 85 c9 74 14 83 f9 13 0f 82 ba } /* Opcode */
		$op1 = { ff 15 34 20 00 10 85 c0 59 a3 60 30 00 10 75 04 } }

Matches rule APT_UNC1151_WindowsInstaller_Silent_InstallProduct_MacroMethod from malware by Proofpoint Threat Research

AuthorProofpoint Threat Research

Matched Strings

$doc_header
Offset (hex) Offset (dec) Length Matched Data
0x3B799C 3897756 8 \xD0\xCF\x11\xE0\xA1\xB1\x1A\xE1
rule APT_UNC1151_WindowsInstaller_Silent_InstallProduct_MacroMethod
{
    meta:
        author = "Proofpoint Threat Research"
        date = "2021-07-28"
        hash1 = "1561ece482c78a2d587b66c8eaf211e806ff438e506fcef8f14ae367db82d9b3"
        hash2 = "a8fd0a5de66fa39056c0ddf2ec74ccd38b2ede147afa602aba00a3f0b55a88e0"
        reference = "Thttps://www.proofpoint.com/us/blog/threat-insight/asylum-ambuscade-state-actor-uses-compromised-private-ukrainian-military-emails"
        id = "9ae80d54-33b9-55d7-957f-0738243e089f"
    strings:
        $doc_header = {D0 CF 11 E0 A1 B1 1A E1}
        $s1 = ".UILevel = 2"
        $s2 = "CreateObject(\"Wind}

Matches rule CoreImpact_sysdll_exe from malware by Florian Roth (Nextron Systems)

Detects a malware sysdll.exe from the Rocket Kitten APT

AuthorFlorian Roth (Nextron Systems)

Matched Strings

$s5
Offset (hex) Offset (dec) Length Matched Data
0x4267FD 4351997 9 127.0.0.1
rule CoreImpact_sysdll_exe
{ RocketKitten and WoolenGoldfish APT
*/


rule CoreImpact_sysdll_exe {
   meta:
      description = "Detects a malware sysdll.exe from the Rocket Kitten APT"
      author = "Florian Roth (Nextron Systems)"
      score = 70
      date = "27.12.2014"
      modified = "2023-01-06"
      hash = "f89a4d4ae5cca6d69a5256c96111e707"
      id = "bac55c00-5d14-59ca-8597-f52b4577be0c"
   strings:
      $s0 = "d:\\nightly\\sandbox_avg10_vc9_SP1_2011\\source\\avg10\\avg9_all_vs90\\bin\\Rele" ascii

      $s1 = "Mozilla/5.0" fullword ascii
      $s3 = "index.php?c=%s&r=%lx" fullword ascii
      $s4 = "index.php?c=%s&r=%x" fullword ascii
      $s5 = "127.0.0.1" fullword ascii
      $s6 = "/info.dat" ascii
      $s7 = "needroot" fullword asci}

Matches rule Dridex_Trojan_XML from malware by Florian Roth (Nextron Systems) @4nc4p

Dridex Malware in XML Document

AuthorFlorian Roth (Nextron Systems) @4nc4p

Matched Strings

$c_xml
Offset (hex) Offset (dec) Length Matched Data
0xA52CA1 10824865 14 <?xml version=
0xB07510 11564304 14 <?xml version=
rule Dridex_Trojan_XML
{
	meta:
		description = "Dridex Malware in XML Document"
		author = "Florian Roth (Nextron Systems) @4nc4p"
		reference = "https://threatpost.com/dridex-banking-trojan-spreading-via-macros-in-xml-files/111503"
		date = "2015/03/08"
		hash1 = "88d98e18ed996986d26ce4149ae9b2faee0bc082"
		hash2 = "3b2d59adadf5ff10829bb5c27961b22611676395"
		hash3 = "e528671b1b32b3fa2134a088bfab1ba46b468514"
		hash4 = "981369cd53c022b434ee6d380aa9884459b63350"
		hash5 = "96e1e7383457293a9b8f2c75270b58da0e630bea"
		id = "a8f3406c-f8b0-559f-be12-6b2a7d401ac2"
	strings:
		// can be ascii or wide formatted - therefore no restriction
		$c_xml      = "<?xml version="
		$c_word     = "<?mso-application progid=\"Word.Document\"?>"
		$c_macro    = "w:macrosPresent=\"yes\""
		$c_binary   }

Matches rule Exploit_MS15_077_078 from exploit

MS15-078 / MS15-077 exploit - generic signature

Matched Strings

$s6
Offset (hex) Offset (dec) Length Matched Data
0x417FD6 4292566 12 DeleteObject
0x9AC20B 10142219 12 DeleteObject
rule Exploit_MS15_077_078
{n Roth
	Date: 2015-07-21
	Identifier: MS15-077 MS15-078
*/

/* Rule Set ----------------------------------------------------------------- */

rule Exploit_MS15_077_078 {
	meta:
		description = "MS15-078 / MS15-077 exploit - generic signature"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://code.google.com/p/google-security-research/issues/detail?id=473&can=1&start=200"
		date = "2015-07-21"
		hash1 = "18e3e840a5e5b75747d6b961fca66a670e3faef252aaa416a88488967b47ac1c"
		hash2 = "0b5dc030e73074b18b1959d1cf7177ff510dbc2a0ec2b8bb927936f59eb3d14d"
		hash3 = "fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9"
		hash4 = "ad6bb982a1ecfe080baf0a2b27950f989c107949b1cf02b6e0907f1a568ece15"
		id = "57f6db11-9d93-53fd-ab68-c6c3eadae2da"
	strings:
		$s1 = "GDI32.DLL" fullword ascii
		$s2 = "atmfd.dll" fullword wide
		$s3 = "AddFontMemResourceEx" fullword ascii
		$s4 = "NamedEscape" fullword ascii
		$s5 = "CreateBitmap" fullword ascii
		$s6 = "DeleteObject" fu}

Matches rule FSO_s_indexer from malware

Webshells Auto-generated - file indexer.asp

50×

Matched Strings

$s3
50×
Offset (hex) Offset (dec) Length Matched Data
0x194 404 1
0x284 644 1
0xBA1 2977 1
0xBD2 3026 1
0xBDB 3035 1
0xC04 3076 1
0xC08 3080 1
0xC1F 3103 1
0xC4E 3150 1
0xC52 3154 1
0xC7F 3199 1
0xC88 3208 1
0xCB5 3253 1
0xCB9 3257 1
0xCC9 3273 1
0xCEB 3307 1
0xD33 3379 1
0xD3A 3386 1
0x1544 5444 1
0x17DC 6108 1
0x182D 6189 1
0x1830 6192 1
0x18E3 6371 1
0x196F 6511 1
0x1987 6535 1
0x1A83 6787 1
0x1B48 6984 1
0x1BF1 7153 1
0x1C7F 7295 1
0x1D9A 7578 1
0x21B3 8627 1
0x23E7 9191 1
0x2518 9496 1
0x25F6 9718 1
0x27C0 10176 1
0x294A 10570 1
0x2B7E 11134 1
0x2CAF 11439 1
0x2D8D 11661 1
0x2F57 12119 1
0x2FF8 12280 1
0x3081 12417 1
0x3233 12851 1
0x32E3 13027 1
0x33C1 13249 1
0x3509 13577 1
0x3589 13705 1
0x3612 13842 1
0x37C8 14280 1
0x387D 14461 1
rule FSO_s_indexer
{ithub Archive - file matamu.php"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		hash = "d477aae6bd2f288b578dbf05c1c46b3aaa474733"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s2 = "$command .= ' -F';" fullword
		$s3 = "/* We try and match a cd command. */" fullword
		}

Matches rule MAL_Sharpshooter_Excel4 from malware by John Lambert, Florian Roth

Detects Excel documents weaponized with Sharpshooter

AuthorJohn Lambert, Florian Roth

Matched Strings

$header_docf
Offset (hex) Offset (dec) Length Matched Data
0x3B799C 3897756 4 \xD0\xCF\x11\xE0
$f1
Offset (hex) Offset (dec) Length Matched Data
0x418506 4293894 12 CreateThread
0x97231F 9904927 12 CreateThread
0x9ACC59 10144857 12 CreateThread
rule MAL_Sharpshooter_Excel4
{
   meta:
      description = "Detects Excel documents weaponized with Sharpshooter"
      author = "John Lambert, Florian Roth"
      reference = "https://github.com/mdsecactivebreach/SharpShooter"
      reference2="https://outflank.nl/blog/2018/10/06/old-school-evil-excel-4-0-macros-xlm/"
      reference3 = "https://gist.github.com/JohnLaTwC/efab89650d6fcbb37a4221e4c282614c"
      reference4 = "https://docs.microsoft.com/en-us/openspecs/office_file_formats/ms-xls/00b5dd7d-51ca-4938-b7b7-483fe0e5933b"
      date = "2020-03-27"
      score = 70
      hash="ccef64586d25ffcb2b28affc1f64319b936175c4911e7841a0e28ee6d6d4a02d"
      id = "a79e3afe-e8f9-5e56-a131-bb1b346df471"
   strings:
      $header_docf = { D0 CF 11 E0 }
      $s1 = "Excel 4.0 Macros"
      $f1 = "CreateThread" ascii fullword
      $f2 }

Matches rule MAL_WIN_Ralordv1_Apr25 from malware by 0x0d4y-Icaro Cesar

This ISH Tecnologia Yara rule, detects the main components of the first version of RALord Ransomware

Author0x0d4y-Icaro Cesar

Matched Strings

$ralord_str_V
Offset (hex) Offset (dec) Length Matched Data
0x40AC56 4238422 5 /rust
0x99CFB7 10080183 5 /rust
rule MAL_WIN_Ralordv1_Apr25
{
    meta:
        description = "This ISH Tecnologia Yara rule, detects the main components of the first version of RALord Ransomware"
        author = "0x0d4y-Icaro Cesar"
        date = "2025-04-01"
        score = 80
        reference = "https://ish.com.br/wp-content/uploads/2025/04/RALord-Novo-grupo-de-Ransomware-as-a-Service-1.pdf"
        hash = "BE15F62D14D1CBE2AECCE8396F4C6289"
        id = "67254633-3597-4770-9806-8b2e26c8f66a"
        license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
        rule_matching_tlp = "TLP:WHITE"
        rule_sharing_tlp = "TLP:WHITE"
        malpedia_family = "win.ralord"

    strings:
        $code_pattern_quarterround = { 4? 31 ?? 48 8b ?? ?? ?? 4? 31 ?? 48 8b ?? ?? ?? 31 e8 4? 31 ?? 41 c1 ?? 0c c1 ?? 0c c1 ?? 0c 48 89 c2 c1 ?? 0c }
        $code_pattern_custom_alg = { 0f 57 ?? 0f 10 ?? c5 ?? ?? ?? ?? 0f 57 ?? 0f 10 ?? c5 ?? ?? ?? ?? 0f 57 ?? 0f 10 ?? c5 ?? ?? ?? ?? 0f 57 ?? 0f 11 ?? c5 ?? ?? ?? ?? 0f 11 ?? c5 ?? ?? ?? ?? 0f 11 ?? c5 ?? ?? ?? ?? 0f 11 ?? c5 ?? ?? ?? ?? 48 83 c0 08 48 3d 8? }
        $ralord_str_I = "chacha" ascii
        $ralord_str_II = "scorp" ascii
        $ralord_str_III = "RALord" ascii
        $ralord_str_IV = "onion" ascii
        $ralord_str_V = "/rust" ascii
        $ralord_str_VI}

Matches rule M_Hunting_Python_Backdoor_CommandParser_1 from malware by Mandiant

Finds strings indicative of the vmsyslog.py python backdoor.

70×
AuthorMandiant

Matched Strings

$key2
15×
Offset (hex) Offset (dec) Length Matched Data
0x3A7855 3831893 6 upload
0x8DD874 9295988 6 upload
0x8DE431 9298993 6 upload
0x8DE460 9299040 6 upload
0x978CFD 9932029 6 upload
0x99A06A 10068074 6 upload
0x99A728 10069800 6 upload
0x99A810 10070032 6 upload
0x99A823 10070051 6 upload
0x99A856 10070102 6 upload
0x99A918 10070296 6 upload
0x99AA46 10070598 6 upload
0x99AB9C 10070940 6 upload
0x99ABF9 10071033 6 upload
0x99AC47 10071111 6 upload
$key3
46×
Offset (hex) Offset (dec) Length Matched Data
0x3AC4EE 3851502 8 download
0x3AC4F9 3851513 8 download
0x3AC527 3851559 8 download
0x3BEFC5 3928005 8 download
0x3CDA3D 3988029 8 download
0x3CDA61 3988065 8 download
0x3CDD1D 3988765 8 download
0x3CDDE7 3988967 8 download
0x3CDE0F 3989007 8 download
0x3CDF3F 3989311 8 download
0x3CE178 3989880 8 download
0x3CE1AA 3989930 8 download
0x3CE1E0 3989984 8 download
0x3CE1F1 3990001 8 download
0x3CE1FC 3990012 8 download
0x8DDCF9 9297145 8 download
0x8DDD0D 9297165 8 download
0x8E32DF 9319135 8 download
0x8E32EA 9319146 8 download
0x8E3318 9319192 8 download
0x8FA266 9413222 8 download
0x902600 9446912 8 download
0x9377BE 9664446 8 download
0x9377E2 9664482 8 download
0x937A9E 9665182 8 download
0x937B68 9665384 8 download
0x937B90 9665424 8 download
0x937CC0 9665728 8 download
0x937EF9 9666297 8 download
0x937F2B 9666347 8 download
0x937F61 9666401 8 download
0x937F72 9666418 8 download
0x937F7D 9666429 8 download
0x97F511 9958673 8 download
0x981A70 9968240 8 download
0x9820DF 9969887 8 download
0x9C4185 10240389 8 download
0x9C795D 10254685 8 download
0x9C8209 10256905 8 download
0x9C826D 10257005 8 download
0x9C882D 10258477 8 download
0x9CBFB5 10272693 8 download
0x9CFA05 10287621 8 download
0x9D02B1 10289841 8 download
0x9D0315 10289941 8 download
0x9D08E1 10291425 8 download
$key4
Offset (hex) Offset (dec) Length Matched Data
0x3BF8AB 3930283 5 shell
0x8FAB4C 9415500 5 shell
$key5
Offset (hex) Offset (dec) Length Matched Data
0x3ABFB0 3850160 7 execute
0x3BF941 3930433 7 execute
0x8E2DA1 9317793 7 execute
0x8FABE2 9415650 7 execute
0x97CE07 9948679 7 execute
0x9C8595 10257813 7 execute
0x9D0649 10290761 7 execute
rule M_Hunting_Python_Backdoor_CommandParser_1
{_Hunting_Python_Backdoor_CommandParser_1 {
   meta:
      author = "Mandiant"
      md5 = "61ab3f6401d60ec36cd3ac980a8deb75"
      description = "Finds strings indicative of the vmsyslog.py python backdoor."
      id = "15cbca01-24e6-5538-bcfd-c3222337aaf5"
   strings:
      $key1 = "self.conn.readInt8()" ascii
      $key2 = "upload" ascii
      $key3 = "download" ascii
      $key4 = "shell" ascii
      $key5 = "execute" ascii
      $re1 = /def\srun.{0,20}command\s?=\s?self\.conn\.readInt8\(\).{,75}upload.{,75}download.{,75}shell.{,75}execute/s
   conditio}

Matches rule Microcin_Sample_1 from malware

Malware sample mentioned in Microcin technical report by Kaspersky

Matched Strings

$s1
Offset (hex) Offset (dec) Length Matched Data
0x39DCB8 3792056 23 e Class Descriptor at (
0x8D1749 9246537 23 e Class Descriptor at (
rule Microcin_Sample_1
{
   Date: 2017-09-26
   Identifier: Microcin
   Reference: https://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf
*/

/* Rule Set ----------------------------------------------------------------- */

import "pe"

rule Microcin_Sample_1 {
   meta:
      description = "Malware sample mentioned in Microcin technical report by Kaspersky"
      license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf"
      date = "2017-09-26"
      hash1 = "49816eefcd341d7a9c1715e1f89143862d4775ba4f9730397a1e8529f5f5e200"
      hash2 = "a73f8f76a30ad5ab03dd503cc63de3a150e6ab75440c1060d75addceb4270f46"
      hash3 = "9dd9bb13c2698159eb78a0ecb4e8692fd96ca4ecb50eef194fa7479cb65efb7c"
      id = "96e9ac3b-a837-5909-b17b-259d54e0e7fd"
   strings:
      $s1 = "e Class Descriptor at (" ascii
      $s2 = ".?AVCAntiAntiAppleFra}

Matches rule OilRig_RGDoor_Gen1 from malware

Detects RGDoor backdoor used by OilRig group

Matched Strings

$c2
Offset (hex) Offset (dec) Length Matched Data
0x3CEF7F 3993471 6 can't
0x3CF247 3994183 6 can't
0x938D00 9669888 6 can't
0x938FE8 9670632 6 can't
rule OilRig_RGDoor_Gen1
{   Date: 2018-01-27
   Identifier: RGDoor
   Reference: https://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/
*/

import "pe"

/* Rule Set ----------------------------------------------------------------- */

rule OilRig_RGDoor_Gen1 {
   meta:
      description = "Detects RGDoor backdoor used by OilRig group"
      license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/"
      date = "2018-01-27"
      score = 80
      hash1 = "a9c92b29ee05c1522715c7a2f9c543740b60e36373cb47b5620b1f3d8ad96bfa"
      id = "68ac1f35-4eaa-5899-b66c-296d7c5fa462"
   strings:
      $c1 = { 00 63 6D 64 24 00 00 00 00 72 00 00 00 00 00 00 00 75 70 6C 6F
              61 64 24 }
      $c2 = { 63 61 6E 27 74 20}

Matches rule OpCloudHopper_Malware_10 from malware

Detects malware from Operation Cloud Hopper

Matched Strings

$s2
Offset (hex) Offset (dec) Length Matched Data
0x39DC70 3791984 12 operator ""
0x8D1701 9246465 12 operator ""
rule OpCloudHopper_Malware_10
{23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html"
      date = "2017-04-03"
      hash1 = "19aa5019f3c00211182b2a80dd9675721dac7cfb31d174436d3b8ec9f97d898b"
      hash2 = "5cebc133ae3b6afee27beb7d3cdb5f3d675c3f12b7204531f453e99acdaa87b1"
      id = "5e0a09e3-732a-5a90-9d4a-11eae2aa4cc4"
   strings:
      $s1 = "WSHELL32.dll" fullword wide
      $s2 = "operator \"\" " fullword ascii
      $s3 = "\" /t REG_SZ /d \"" fullword wide
      $s4 = " /f /v \"" fullw}

Matches rule PUA_VULN_Driver_Novellinc_Novellxtier_7627

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3C5A 10304602 22 \x00P\x00r\x00o\x00d\x00u\x00c\x00t\x00V\x00e\x00r\x00s
0xB07345 11563845 22 \x00P\x00r\x00o\x00d\x00u\x00c\x00t\x00V\x00e\x00r\x00s

Matches rule PUA_VULN_Driver_Tgsoftsas_Viragtsys_Viritagentsystem_E05E

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3BCE 10304462 7 \x00O\x00r\x00i\x00
0xB072A9 11563689 7 \x00O\x00r\x00i\x00

Matches rule PUA_VULN_Driver_Trendmicroinc_Tmelsys_Trendmicroearlylaunchantimalwaredriver_DD62

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3BCE 10304462 25 \x00O\x00r\x00i\x00g\x00i\x00n\x00a\x00l\x00F\x00i\x00l\x00e\x00
0xB072A9 11563689 25 \x00O\x00r\x00i\x00g\x00i\x00n\x00a\x00l\x00F\x00i\x00l\x00e\x00

Matches rule PUA_VULN_Renamed_Driver_Avastsoftware_Aswarpotsys_Avastantivirus_EBE2

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3B4A 10304330 19 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00
0xB07225 11563557 19 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00

Matches rule PUA_VULN_Renamed_Driver_Cpuid_Cpuzsys_Cpuidservice_0D37 from malware by Florian Roth

Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - cpuz.sys

AuthorFlorian Roth

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3B4A 10304330 29 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
0xB07225 11563557 29 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
rule PUA_VULN_Renamed_Driver_Cpuid_Cpuzsys_Cpuidservice_0D37
{730068002000440072006900760065007200200066006f0072002000570069006e0064006f007700730020004e0054 } /* FileDescription SWinFlashDriverforWindowsNT */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]00500068006f0065006e0069007800200054006500630068006e006f006c006f0067006900650073002c0020004c00740064002e } /* CompanyName PhoenixTechnologiesLtd */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0031002e0036002e0031002e0030 } /* FileVersion  */
		$ = { 00500072006f006400750063007400560065007200730069006f006e[1-8]0031002e0036002e0031002e0030 } /* ProductVersion  */
		$ = { 0049006e007400650072006e0061006c004e0061006d0065[1-8]00500048004c004100530048004e0054 } /* InternalName PHLASHNT */
		$ = { 00500072006f0064007500630074004e0061006d0065[1-8]00570069006e00500068006c006100730068 } /* ProductName WinPhlash */
		$ = { 004f0072006900670069006e0061006c00460069006c0065006e0061006d0065[1-8]00500048004c004100530048004e0054002e005300590053 } /* OriginalFilename PHLASHNTSYS */
		$ = { 004c006500670061006c0043006f0070007900720069006700680074[1-8]002800630029002000500068006f0065006e0069007800200054006500630068006e006f006c006f0067006900650073002c0020004c00740064002e00200032003000300030002d0032003000300033 } /* LegalCopyright cPhoenixTechnologiesLtd */
	condition:
		uint16(0) == 0x5a4d and filesize < 100KB and all of them and not filename matches /PhlashNT/i
}


rule PUA_VULN_Renamed_Driver_Arthurliberman_Alsysiosys_Alsysio_7196 {
	meta:
		description = "Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - ALSysIO64.sys"
		author = "Florian Roth"
		reference = "https://github.com/magicsword-io/LOLDrivers"
		hash = "7196187fb1ef8d108b380d37b2af8efdeb3ca1f6eefd37b5dc114c609147216d"
		date = "2024-08-07"
		score = 70
		id = "a197bb49-05c6-5f73-a598-2df9ff503ffa"
	strings:
		$ = { 00460069006c0065004400650073006300720069007000740069006f006e[1-8]0041004c0053007900730049004f } /* FileDescription ALSysIO */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]0041007200740068007500720020004c0069006200650072006d0061006e } /* CompanyName ArthurLiberman */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0032002e0030002e0038002e0030 } /* FileVersion  */
		$ = { 00500072006f006400750063007400560065007200730069006f006e[1-8]0032002e0030002e0038002e0030 } /* ProductVersion  */
		$ = { 0049006e007400650072006e0061006c004e0061006d0065[1-8]0041004c0053007900730049004f002e007300790073 } /* InternalName ALSysIOsys */
		$ = { 00500072006f0064007500630074004e0061006d0065[1-8]0041004c0053007900730049004f } /* ProductName ALSysIO */
		$ = { 004f0072006900670069006e0061006c00460069006c0065006e0061006d0065[1-8]0041004c0053007900730049004f002e007300790073 } /* OriginalFilename ALSysIOsys */
		$ = { 004c006500670061006c0043006f0070007900720069006700680074[1-8]0043006f0070007900720069006700680074002000280043002900200032003000300033002d003200300030003900200041007200740068007500720020004c0069006200650072006d0061006e } /* LegalCopyright CopyrightCArthurLiberman */
	condition:
		uint16(0) == 0x5a4d and filesize < 100KB and all of them and not filename matches /ALSysIO64/i
}


rule PUA_VULN_Renamed_Driver_Advancedmicrodevices_Aoddriversys_Amdoverdriveservicedriver_F4DC {
	meta:
		description = "Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - AODDriver.sys"
		author = "Florian Roth"
		reference = "https://github.com/magicsword-io/LOLDrivers"
		hash = "f4dc11b7922bf2674ca9673638e7fe4e26aceb0ebdc528e6d10c8676e555d7b2"
		hash = "070ff602cccaaef9e2b094e03983fd7f1bf0c0326612eb76593eabbf1bda9103"
		date = "2024-08-07"
		score = 70
		id = "44890447-4682-561a-9009-adc3e3b9ac57"
	strings:
		$ = { 00460069006c0065004400650073006300720069007000740069006f006e[1-8]0041004d00440020004f00760065007200440072006900760065002000530065007200760069006300650020004400720069007600650072 } /* FileDescription AMDOverDriveServiceDriver */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]0041006400760061006e0063006500640020004d006900630072006f00200044006500760069006300650073 } /* CompanyName AdvancedMicroDevices */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0034002e0032002e00300020006200750069006c0074002000620079003a002000570069006e00440044004b } /* Fi}

Matches rule PUA_VULN_Renamed_Driver_Intelcorporation_Iqvwsys_Intelriqvwsys_1F81

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3B4A 10304330 41 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00
0xB07225 11563557 41 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00

Matches rule PUA_VULN_Renamed_Driver_Novellinc_Novellxtier_1493

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3BCE 10304462 14 \x00O\x00r\x00i\x00g\x00i\x00n\x00a
0xB072A9 11563689 14 \x00O\x00r\x00i\x00g\x00i\x00n\x00a

Matches rule PUA_VULN_Renamed_Driver_Radiantsystemsinc_Radhwmgrsys_Radiantsystemsinchardwaremanagerdriver_0F30

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3B4A 10304330 23 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00
0xB07225 11563557 23 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00

Matches rule PUA_VULN_Renamed_Driver_Realteksemiconductorcorp_Rtportsys_Realtekportio_FF32

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x9D3B4A 10304330 44 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00i\x00g
0xB07225 11563557 44 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00i\x00g

Matches rule PUA_VULN_Renamed_Driver_Sysinternalswwwsysinternalscom_Procexpsys_7795

48×

Matched Strings

$
48×
Offset (hex) Offset (dec) Length Matched Data
0x9D3C0E 10304526 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9D3C5A 10304602 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9D3CD2 10304722 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9E0A5A 10357338 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9EE19A 10412442 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F03D0 10421200 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F138C 10425228 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F322C 10433068 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F421E 10437150 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F4FBA 10440634 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F5F1A 10444570 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F71D0 10449360 11 \x00P\x00r\x00o\x00d\x00u\x00
0x9F9746 10458950 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA081CA 10518986 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA0A1B2 10527154 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA11E08 10558984 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA1ABEA 10595306 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA1F20C 10613260 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA2E8F4 10676468 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA341E6 10699238 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA36B12 10709778 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA3ABB2 10726322 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA4DC5E 10804318 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA5114A 10817866 11 \x00P\x00r\x00o\x00d\x00u\x00
0xA94FDD 11096029 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA26F9 11151097 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA492B 11159851 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA58DF 11163871 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA775B 11171675 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA8739 11175737 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAA94C9 11179209 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAAA419 11183129 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAAB6BF 11187903 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAADC25 11197477 11 \x00P\x00r\x00o\x00d\x00u\x00
0xABC65D 11257437 11 \x00P\x00r\x00o\x00d\x00u\x00
0xABE639 11265593 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAC625B 11297371 11 \x00P\x00r\x00o\x00d\x00u\x00
0xACF01D 11333661 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAD361F 11351583 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAE2CC7 11414727 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAE85A9 11437481 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAEAED1 11448017 11 \x00P\x00r\x00o\x00d\x00u\x00
0xAEEF51 11464529 11 \x00P\x00r\x00o\x00d\x00u\x00
0xB01FD9 11542489 11 \x00P\x00r\x00o\x00d\x00u\x00
0xB054C1 11556033 11 \x00P\x00r\x00o\x00d\x00u\x00
0xB072F5 11563765 11 \x00P\x00r\x00o\x00d\x00u\x00
0xB07345 11563845 11 \x00P\x00r\x00o\x00d\x00u\x00
0xB073BD 11563965 11 \x00P\x00r\x00o\x00d\x00u\x00

Matches rule SUSP_EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22_1 from exploit by Florian Roth

Detects payload as seen in PoC code to exploit Workspace ONE Access freemarker server-side template injection CVE-2022-22954

19×
AuthorFlorian Roth

Matched Strings

$fpg2
Offset (hex) Offset (dec) Length Matched Data
0x9791EF 9933295 5 <html
0x97E65E 9954910 5 <html
0x97E8D3 9955539 5 <html
0x988DD5 9997781 5 <html
0x993070 10039408 5 <html
0x993BBB 10042299 5 <html
0x994145 10043717 5 <html
0x994373 10044275 5 <html
0x9944DD 10044637 5 <html
$fpg4
Offset (hex) Offset (dec) Length Matched Data
0x8F3A2E 9386542 9 Copyright
0x983747 9975623 9 Copyright
0x9843C8 9978824 9 Copyright
0x9D3B55 10304341 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
0x9D3B69 10304361 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
0xB07230 11563568 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
0xB07244 11563588 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
$fpg5
Offset (hex) Offset (dec) Length Matched Data
0x97D70D 9950989 7 License
$fpg6
Offset (hex) Offset (dec) Length Matched Data
0xA52CA1 10824865 5 <?xml
0xB07510 11564304 5 <?xml
rule SUSP_EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22_1
{
   meta:
      old_rule_name = "EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22"
      description = "Detects payload as seen in PoC code to exploit Workspace ONE Access freemarker server-side template injection CVE-2022-22954"
      author = "Florian Roth"
      reference = "https://github.com/sherlocksecurity/VMware-CVE-2022-22954"
      reference2 = "https://twitter.com/rwincey/status/1512241638994853891/photo/1"
      date = "2022-04-08"
      modified = "2025-03-29"
      score = 60
      id = "3ff617bb-6dcd-576f-a1c3-7be1c19c0d5a"
   strings:
      $x2 = "${\"freemarker.template.utility.Execute\"?new()("
      $x3 = "cat /etc/passwd\")).(#execute=#instancemanager.newInstance(\"freemarker.template.utility.Execute"
      $x4 = "cat /etc/passwd\\\")).(#execute=#instancemanager.newInstance(\\\"freemarker.template.utility.Execute"
      $x5 = "cat /etc/shadow\")).(#execute=#instancemanager.newInstance(\"freemarker.template.utility.Execute"
      $x6 = "cat /etc/shadow\\\")).(#execute=#instancemanager.newInstance(\\\"freemarker.template.utility.Execute"

      $fpg1 = "All Rights"
      $fpg2 = "<html"
      $fpg3 = "<HTML"
      $fpg4 = "Copyright" ascii wide
      $fpg5 = "License"
      $fpg6 = "<?xml"
      $fpg7 = "Help" fullword
      $fpg8 = "COPYRIGHT" ascii wide fullword
      $fpg}

Matches rule SUSP_IIS_Config_VirtualDir from malware by Florian Roth (Nextron Systems)

Detects suspicious virtual directory configured in IIS pointing to a User folder

AuthorFlorian Roth (Nextron Systems)

Matched Strings

$g6
Offset (hex) Offset (dec) Length Matched Data
0x990A38 10029624 16 script language=
0x9923C8 10036168 16 script language=
rule SUSP_IIS_Config_VirtualDir
{on = "Webshells generated by an Mailbox export to PST and stored as aspx: 570221043.aspx 689193944.aspx luifdecggoqmansn.aspx"
      author = "Moritz Oettle"
      reference = "https://github.com/hvs-consulting/ioc_signatures/tree/main/Proxyshell"
      date = "2021-09-04"
      score = 85
      id = "6aea414f-d27c-5202-84f8-b8620782fc90"
   strings:
      $x1 = "!BDN"  /* PST file header */

      $g1 = "Page language=" ascii
      $g2 = "<%@ Page" ascii
      $g3 = "Request.Item[" ascii
      $g4 = "\"unsafe\");" ascii
      $g5 = "<%eval(" ascii
      $g6 = "script language=" ascii
      $g7 = "Request[" ascii

      $s1 = "gold8899" ascii  /* HTTP Request Parameter */
      $s2 }

Matches rule SUSP_Known_Type_Cloaked_as_JPG from malware by Florian Roth (Nextron Systems)

Detects a non-JPEG file type cloaked as .jpg

23×
AuthorFlorian Roth (Nextron Systems)

Matched Strings

$mz
21×
Offset (hex) Offset (dec) Length Matched Data
0x0 0 2 MZ
0x16BB5F 1489759 2 MZ
0x21E467 2221159 2 MZ
0x21EEF8 2223864 2 MZ
0x22D3DF 2282463 2 MZ
0x2437A7 2373543 2 MZ
0x3AAF00 3845888 2 MZ
0x3AAF04 3845892 2 MZ
0x3AAF0C 3845900 2 MZ
0x3AAF10 3845904 2 MZ
0x426861 4352097 2 MZ
0x6D0138 7143736 2 MZ
0x6D0C69 7146601 2 MZ
0x6DF160 7205216 2 MZ
0x6F6618 7300632 2 MZ
0x8BB902 9156866 2 MZ
0x8BBAE2 9157346 2 MZ
0x92F049 9629769 2 MZ
0x99512C 10047788 2 MZ
0x99CF11 10080017 2 MZ
0xA7D629 10999337 2 MZ
$a1
Offset (hex) Offset (dec) Length Matched Data
0x4E 78 38 This program cannot be run in DOS mode
0x4268AF 4352175 38 This program cannot be run in DOS mode
rule SUSP_Known_Type_Cloaked_as_JPG
{gmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md)

*/

/* Performance killer - value isn't big enough
rule Embedded_EXE_Cloaking {
        meta:
                description = "Detects an embedded executable in a non-executable file"
                license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
                date = "2015/02/27"
                score = 65
        strings:
                $noex_png = { 89 50 4E 47 }
                $noex_pdf = { 25 50 44 46 }
                $noex_rtf = { 7B 5C 72 74 66 31 }
                $noex_jpg = { FF D8 FF E0 }
                $noex_gif = { 47 49 46 38 }
                $mz  = { 4D 5A }
                $a1 = "This program cannot be run in DOS mode"
                $a2 = "This progr}

Matches rule SUSP_NK_MAL_M_Hunting_POOLRAT from malware by Mandiant

Detects strings found in POOLRAT malware

AuthorMandiant

Matched Strings

$ss6
Offset (hex) Offset (dec) Length Matched Data
0x3B5966 3889510 11 CreateFileW
0x41849A 4293786 11 CreateFileW
0x9ACBD9 10144729 11 CreateFileW
rule SUSP_NK_MAL_M_Hunting_POOLRAT
{7a1e1f922b99b09b77"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "2cbedbc0-d465-5674-bf9c-9362003eb8d2"
   strings:
      $ss1 = "C:\\Programdata\\" wide
      $ss2 = "devobj.dll" wide fullword
      $ss3 = "msvcr100.dll" wide fullword
      $ss4 = "TpmVscMgrSvr.exe" wide fullword
      $ss5 = "\\Microsoft\\Windows\\TPM" wide fullword
      $ss6 = "CreateFileW" ascii fullword
   condition:
      (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x010B) and all of them
}

rule SUSP_NK_MAL_M_Hunting_POOLRAT {
   meta:
      description = "Detects VEILEDSIGNAL malware"
      author = "Mandiant"
      old_rule_name = "APT_NK_MAL_M_Hunting_POOLRAT"
      score = 70
      disclai}

Matches rule SUSP_PS1_JAB_Pattern_Jun22_1 from malware by Florian Roth (Nextron Systems)

Detects suspicious UTF16 and Base64 encoded PowerShell code that starts with a $ sign and a single char variable

24×
AuthorFlorian Roth (Nextron Systems)

Matched Strings

$xc1
24×
Offset (hex) Offset (dec) Length Matched Data
0x13B65 80741 2 JA
0x78362 492386 2 JA
0xE0C52 920658 2 JA
0x3A2D01 3812609 2 JA
0x3A2D99 3812761 2 JA
0x3A2E69 3812969 2 JA
0x3A2FF9 3813369 2 JA
0x3A3241 3813953 2 JA
0x3A339D 3814301 2 JA
0x3A49AD 3819949 2 JA
0x3A4F25 3821349 2 JA
0x4644E3 4605155 2 JA
0x8CD743 9230147 2 JA
0x90B7CD 9484237 2 JA
0x90CAE3 9489123 2 JA
0x90CB1E 9489182 2 JA
0x90CB92 9489298 2 JA
0x90CC6E 9489518 2 JA
0x920824 9570340 2 JA
0x927C72 9600114 2 JA
0x92AA3A 9611834 2 JA
0x930A14 9636372 2 JA
0x9A9682 10131074 2 JA
0x9AE98A 10152330 2 JA
rule SUSP_PS1_JAB_Pattern_Jun22_1
{
   meta:
      description = "Detects suspicious UTF16 and Base64 encoded PowerShell code that starts with a $ sign and a single char variable"
      author = "Florian Roth (Nextron Systems)"
      reference = "Internal Research"
      date = "2022-06-10"
      score= 70
      id = "9ecca7d9-3b63-5615-a223-5efa1c53510e"
   strings:
      /* 
         with spaces : $c = $ 
         https://gchq.github.io/CyberChef/#recipe=Fork('%5C%5Cn','%5C%5Cn',false)Encode_text('UTF-16LE%20(1200)')To_Base64('A-Za-z0-9%2B/%3D')Encode_text('UTF-16LE%20(1200)'/disabled)To_Hex('Space',0)&input=JHAgPSAkRW52OnRlbQokeCA9ICRteXZhcjsKJHggPSBJbnZva2Ut
      */
      /* ASCII */ 
      $xc1 = { 4a 41 4}

Matches rule SVG_LoadURL from malware by Florian Roth

Detects a tiny SVG file that loads an URL (as seen in CryptoWall malware infections)

AuthorFlorian Roth

Matched Strings

$s2
Offset (hex) Offset (dec) Length Matched Data
0x97FEA1 9961121 8 <script>
0x9854D9 9983193 8 <script>
rule SVG_LoadURL
{
	meta:
		description = "Detects a tiny SVG file that loads an URL (as seen in CryptoWall malware infections)"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "http://goo.gl/psjCCc"
		date = "2015-05-24"
		hash1 = "ac8ef9df208f624be9c7e7804de55318"
		hash2 = "3b9e67a38569ebe8202ac90ad60c52e0"
		hash3 = "7e2be5cc785ef7711282cea8980b9fee"
		hash4 = "4e2c6f6b3907ec882596024e55c2b58b"
		score = 50
		id = "c3d4c95f-ef8b-52ff-9cf9-d66d9b99a490"
	strings:
		$s1 = "</svg>" nocase
		$s2 = "<script>" nocase
		$s3 = "loca}

Matches rule StuxNet_Malware_1 from malware by Florian Roth

Stuxnet Sample - file malware.exe

50×
AuthorFlorian Roth

Matched Strings

$op3
50×
Offset (hex) Offset (dec) Length Matched Data
0x32CB1 208049 2 tp
0x35169 217449 2 tp
0x49876 301174 2 tp
0x52AD5 338645 2 tp
0x61A24 399908 2 tp
0x6AB4A 437066 2 tp
0x74C4E 478286 2 tp
0x97F1D 622365 2 tp
0x9F188 651656 2 tp
0xA16CE 661198 2 tp
0xAE3B1 713649 2 tp
0xB8848 755784 2 tp
0xBBBC6 768966 2 tp
0xBCA29 772649 2 tp
0xBD1DB 774619 2 tp
0xCEFCD 847821 2 tp
0xD2607 861703 2 tp
0xD86FA 886522 2 tp
0xE5D3E 941374 2 tp
0xE865C 951900 2 tp
0xE876F 952175 2 tp
0xF11CB 987595 2 tp
0xF655B 1008987 2 tp
0xF7F5C 1015644 2 tp
0x105D32 1072434 2 tp
0x110AF5 1116917 2 tp
0x110DA4 1117604 2 tp
0x116573 1140083 2 tp
0x139B6D 1284973 2 tp
0x13F92A 1308970 2 tp
0x13FBB7 1309623 2 tp
0x13FF07 1310471 2 tp
0x13FFF8 1310712 2 tp
0x167912 1472786 2 tp
0x16901F 1478687 2 tp
0x16EFEB 1503211 2 tp
0x16F19B 1503643 2 tp
0x170146 1507654 2 tp
0x175CF9 1531129 2 tp
0x187C89 1604745 2 tp
0x18E685 1631877 2 tp
0x19266B 1648235 2 tp
0x196FCB 1667019 2 tp
0x1B6906 1796358 2 tp
0x208AE6 2132710 2 tp
0x20F232 2159154 2 tp
0x20F312 2159378 2 tp
0x20F3F3 2159603 2 tp
0x20FB73 2161523 2 tp
0x2231BB 2240955 2 tp
rule StuxNet_Malware_1
{rian Roth
	Date: 2016-07-09
	Identifier: Stuxnet
*/

/* Rule Set ----------------------------------------------------------------- */

rule StuxNet_Malware_1 {
	meta:
		description = "Stuxnet Sample - file malware.exe"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "Internal Research"
		date = "2016-07-09"
		hash1 = "9c891edb5da763398969b6aaa86a5d46971bd28a455b20c2067cb512c9f9a0f8"
		id = "1f475dc3-ebb3-508f-b696-3d9ea270b13d"
	strings:
		 // 0x10001778 8b 45 08  mov     eax, dword ptr [ebp + 8]
		 // 0x1000177b 35 dd 79 19 ae    xor     eax, 0xae1979dd
		 // 0x10001780 33 c9     xor     ecx, ecx
		 // 0x10001782 8b 55 08  mov     edx, dword ptr [ebp + 8]
		 // 0x10001785 89 02     mov     dword ptr [edx], eax
		 // 0x10001787 89 ?? ??  mov     dword ptr [edx + 4], ecx
		 $op1 = { 8b 45 08 35 dd 79 19 ae 33 c9 8b 55 08 89 02 89 }
		 // 0x10002045 74 36     je      0x1000207d
		 // 0x10002047 8b 7f 08  mov     edi, dword ptr [edi + 8]
		 // 0x1000204a 83 ff 00  cmp     edi, 0
		 // 0x1000204d 74 2e     je      0x1000207d
		 // 0x1000204f 0f b7 1f  movzx   ebx, word ptr [edi]
		 // 0x10002052 8b 7f 04  mov     edi, dword ptr [edi + 4]
		 $op2 = { 74 36 8b 7f 08 83 ff 00 74 2e 0f b7 1f 8b 7f 04 }
		 // 0x100020cf 74 70     je      0x10002141
		 // 0x100020d1 81 78 05 8d 54 24 04      cmp     dword ptr [eax + 5], 0x424548d
		 // 0x100020d8 75 1b     jne     0x100020f5
		 // 0x100020da 81 78 08 04 cd ?? ??      cmp     dword ptr [eax + 8], 0xc22ecd04
		 $op3 = { 74 70}

Matches rule TrojanDownloader from malware

Trojan Downloader - Flash Exploit Feb15

32×

Matched Strings

$x2
Offset (hex) Offset (dec) Length Matched Data
0x8DDC54 9296980 6 CONIN$
$s6
Offset (hex) Offset (dec) Length Matched Data
0x41874A 4294474 15 GetCommandLineA
0x9ACEC1 10145473 15 GetCommandLineA
$s7
Offset (hex) Offset (dec) Length Matched Data
0x418600 4294144 11 ExitProcess
0x9ACD41 10145089 11 ExitProcess
$s8
Offset (hex) Offset (dec) Length Matched Data
0x418476 4293750 11 CreateFileA
0x9ACBB5 10144693 11 CreateFileA
$s9
Offset (hex) Offset (dec) Length Matched Data
0x41935E 4297566 16 TerminateProcess
0x9ADC5F 10148959 16 TerminateProcess
$s10
Offset (hex) Offset (dec) Length Matched Data
0x4187AE 4294574 17 GetCurrentProcess
0x9ACF25 10145573 17 GetCurrentProcess
$s11
Offset (hex) Offset (dec) Length Matched Data
0x4193E4 4297700 24 UnhandledExceptionFilter
0x9ADCF9 10149113 24 UnhandledExceptionFilter
$s17
Offset (hex) Offset (dec) Length Matched Data
0x4188EE 4294894 11 GetFileType
0x9AD093 10145939 11 GetFileType
$s20
Offset (hex) Offset (dec) Length Matched Data
0x41947E 4297854 11 VirtualFree
0x9ADDA3 10149283 11 VirtualFree
$s21
Offset (hex) Offset (dec) Length Matched Data
0x3B13F8 3871736 9 WriteFile
0x41956A 4298090 9 WriteFile
0x8ECC40 9358400 9 WriteFile
0x973AED 9911021 9 WriteFile
0x9ADEA1 10149537 9 WriteFile
$s22
Offset (hex) Offset (dec) Length Matched Data
0x418A60 4295264 8 GetOEMCP
0x9AD21D 10146333 8 GetOEMCP
$s23
Offset (hex) Offset (dec) Length Matched Data
0x3B03CA 3867594 12 VirtualAlloc
0x41946E 4297838 12 VirtualAlloc
0x8EBBEB 9354219 12 VirtualAlloc
0x9ADD93 10149267 12 VirtualAlloc
$s24
Offset (hex) Offset (dec) Length Matched Data
0x418A82 4295298 14 GetProcAddress
0x9AD23F 10146367 14 GetProcAddress
$s26
Offset (hex) Offset (dec) Length Matched Data
0x4186CE 4294350 16 FlushFileBuffers
0x9ACE21 10145313 16 FlushFileBuffers
rule TrojanDownloader
{-------------------------------------------------- */

rule TrojanDownloader {
	meta:
		description = "Trojan Downloader - Flash Exploit Feb15"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "http://goo.gl/wJ8V1I"
		date = "2015/02/11"
		hash = "5b8d4280ff6fc9c8e1b9593cbaeb04a29e64a81e"
		score = 60
		id = "d61f59ef-31a3-5e52-9525-61910bb150db"
	strings:
		$x1 = "Hello World!" fullword ascii
		$x2 = "CONIN$" fullword ascii

		$s6 = "GetCommandLineA" fullword ascii
		$s7 = "ExitProcess" fullword ascii
		$s8 = "CreateFileA" fullword ascii

		$s5 = "SetConsoleMode" fullword ascii
		$s9 = "TerminateProcess" fullword ascii
		$s10 = "GetCurrentProcess" fullword ascii
		$s11 = "UnhandledExceptionFilter" fullword ascii
		$s3 = "user32.dll" fullword ascii
		$s16 = "GetEnvironmentStrings" fullword ascii
		$s2 = "GetLastActivePopup" fullword ascii
		$s17 = "GetFileType" fullword ascii
		$s19 = "HeapCreate" fullword ascii
		$s20 = "VirtualFree" fullword ascii
		$s21 = "WriteFile" fullword ascii
		$s22 = "GetOEMCP" fullword ascii
		$s23 = "VirtualAlloc" fullword ascii
		$s24 = "GetProcAddress" fullword ascii
		$s26 = "FlushFileBuffers" fullword asci}

Matches rule UBoatRAT from malware

Detects UBoat RAT Samples

34×

Matched Strings

$vprotect
30×
Offset (hex) Offset (dec) Length Matched Data
0x3BFDC1 3931585 2 .v
0x3BFFE4 3932132 2 .v
0x3C0013 3932179 2 .v
0x3C015A 3932506 2 .v
0x3C0161 3932513 2 .v
0x3C0277 3932791 2 .v
0x3C053C 3933500 2 .v
0x3C08F1 3934449 2 .v
0x3CF8A8 3995816 2 .v
0x3D091B 4000027 2 .v
0x69C27F 6931071 2 .v
0x8FB062 9416802 2 .v
0x8FB285 9417349 2 .v
0x8FB2B4 9417396 2 .v
0x8FB3FB 9417723 2 .v
0x8FB402 9417730 2 .v
0x8FB518 9418008 2 .v
0x8FB7DD 9418717 2 .v
0x8FBB92 9419666 2 .v
0x939649 9672265 2 .v
0x93B19C 9679260 2 .v
0x9783D5 9929685 2 .v
0x97D914 9951508 2 .v
0x9839FD 9976317 2 .v
0xA52CF6 10824950 2 .v
0xA52D41 10825025 2 .v
0xA52EF0 10825456 2 .v
0xB07565 11564389 2 .v
0xB075B0 11564464 2 .v
0xB0775F 11564895 2 .v
$s2
Offset (hex) Offset (dec) Length Matched Data
0x41899C 4295068 18 GetModuleFileNameW
0x9AD159 10146137 18 GetModuleFileNameW
$s6
Offset (hex) Offset (dec) Length Matched Data
0x4199B4 4299188 12 WTSAPI32.dll
0x9AE42F 10150959 12 WTSAPI32.dll
rule UBoatRAT
{t
   Author: Florian Roth
   Date: 2017-11-28
   Identifier: UBoatRAT
   Reference: https://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/
*/

rule UBoatRAT {
   meta:
      description = "Detects UBoat RAT Samples"
      license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/"
      date = "2017-11-29"
      hash1 = "04873dbd63279228a0a4bb1184933b64adb880e874bd3d14078161d06e232c9b"
      hash2 = "7b32f401e2ad577e8398b2975ecb5c5ce68c5b07717b1e0d762f90a6fbd8add1"
      hash3 = "42d8a84cd49ff3afacf3d549fbab1fa80d5eda0c8625938b6d32e18004b0edac"
      hash4 = "6bea49e4260f083ed6b73e100550ecd22300806071f4a6326e0544272a84526c"
      hash5 = "cf832f32b8d27cf9911031910621c21bd3c20e71cc062716923304dacf4dadb7"
      hash6 = "bf7c6e911f14a1f8679c9b0c2b183d74d5accd559e17297adcd173d76755e271"
      id = "f7f745c2-648d-5937-8d06-f5d1b6ed7e11"
   strings:
      $s1 = "URLDownloadToFileA" ascii
      $s2 = "GetModuleFileNameW" ascii
      $s4 = "WININET.dll" ascii
      $s5 = "urlmon.dll" ascii
      $s6 = "WTSAPI32.dll" ascii
      $s7 = "IPHLPAPI.DLL" ascii

      $op1 = { 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68
               69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F
               74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20
               6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 }

      $vprotect = { 2E 76}

Matches rule VUL_Exchange_CVE_2020_0688 from exploit by Florian Roth (Nextron Systems)

Detects static validation key used by Exchange server in web.config

AuthorFlorian Roth (Nextron Systems)

Matched Strings

$h1
Offset (hex) Offset (dec) Length Matched Data
0xA52CA1 10824865 6 <?xml
0xB07510 11564304 6 <?xml
rule VUL_Exchange_CVE_2020_0688
{
   meta:
      description = "Detects static validation key used by Exchange server in web.config"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://www.thezdi.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys"
      date = "2020-02-26"
      score = 60
      id = "1065f297-0dc4-5dcb-b0f3-c89d06ff5e69"
   strings:
      $h1 = "<?xml "
      $x1 = "<machineKey validatio}

Matches rule WEBSHELL_ASP_OBFUSC

167×

Matched Strings

$asp_obf1
50×
Offset (hex) Offset (dec) Length Matched Data
0x52 82 1
0x5A 90 1
0x61 97 1
0x64 100 1
0x68 104 1
0x6B 107 1
0x6F 111 1
0x194 404 1
0x275 629 1
0x284 644 1
0x463 1123 1
0x4ED 1261 1
0x6BE 1726 1
0x759 1881 1
0x98B 2443 1
0xBA1 2977 1
0xBA5 2981 1
0xBD2 3026 1
0xBDB 3035 1
0xC04 3076 1
0xC08 3080 1
0xC10 3088 1
0xC1F 3103 1
0xC4E 3150 1
0xC52 3154 1
0xC7F 3199 1
0xC88 3208 1
0xCB5 3253 1
0xCB9 3257 1
0xCC9 3273 1
0xCEB 3307 1
0xD33 3379 1
0xD3A 3386 1
0xD5E 3422 1
0xD6D 3437 1
0xD71 3441 1
0xD76 3446 1
0xD81 3457 1
0xD84 3460 1
0xFEB 4075 1
0x10D6 4310 1
0x10E2 4322 1
0x10E6 4326 1
0x10EA 4330 1
0x10F5 4341 1
0x10FA 4346 1
0x1102 4354 1
0x110C 4364 1
0x11A4 4516 1
0x132C 4908 1
$susasp10
50×
Offset (hex) Offset (dec) Length Matched Data
0x128821 1214497 2 "
0x26C8DC 2541788 2 "
0x27C48C 2606220 2 "
0x2A536C 2773868 2 "
0x39DC78 3791992 2 "
0x39DF52 3792722 2 "
0x3A74AC 3830956 2 "
0x3A9125 3838245 2 "
0x3B97C4 3905476 2 "
0x3B97F6 3905526 2 "
0x3B980D 3905549 2 "
0x3B9832 3905586 2 "
0x3B984A 3905610 2 "
0x3BEAFC 3926780 2 "
0x3C46B6 3950262 2 "
0x3C46F0 3950320 2 "
0x3C46F2 3950322 2 "
0x3CEE15 3993109 2 "
0x3CF2A0 3994272 2 "
0x3EBD63 4111715 2 "
0x40D039 4247609 2 "
0x42668E 4351630 2 "
0x4266A6 4351654 2 "
0x426763 4351843 2 "
0x44C45D 4506717 2 "
0x4565E1 4548065 2 "
0x456601 4548097 2 "
0x45661B 4548123 2 "
0x4AE784 4908932 2 "
0x4AE804 4909060 2 "
0x4B5BD1 4938705 2 "
0x4B7B8C 4946828 2 "
0x4F8352 5210962 2 "
0x5AC952 5949778 2 "
0x5C9538 6067512 2 "
0x5CC56D 6079853 2 "
0x7F7B6A 8354666 2 "
0x8D1709 9246473 2 "
0x8D19E3 9247203 2 "
0x8DB799 9287577 2 "
0x8DD1F1 9294321 2 "
0x8DE41B 9298971 2 "
0x8DE44B 9299019 2 "
0x8DE45A 9299034 2 "
0x8DEDF1 9301489 2 "
0x8DF996 9304470 2 "
0x8F4845 9390149 2 "
0x8F4877 9390199 2 "
0x8F488E 9390222 2 "
0x8F48B3 9390259 2 "
$tagasp_short2
24×
Offset (hex) Offset (dec) Length Matched Data
0x5B367 373607 2 %>
0x3ED10F 4116751 2 %>
0x410EC1 4263617 2 %>
0x411C39 4267065 2 %>
0x92489A 9586842 2 %>
0x957990 9795984 2 %>
0x9A3222 10105378 2 %>
0x9A3F9A 10108826 2 %>
0xA53B3D 10828605 2 %>
0xA58659 10847833 2 %>
0xA590BD 10850493 2 %>
0xA5C32B 10863403 2 %>
0xA62DBF 10890687 2 %>
0xA637C7 10893255 2 %>
0xA7AC6B 10988651 2 %>
0xB0A9C4 11577796 2 %>
0xB10B3A 11602746 2 %>
0xB1293C 11610428 2 %>
0xB138CE 11614414 2 %>
0xB14D24 11619620 2 %>
0xB19FFE 11640830 2 %>
0xB1C02C 11649068 2 %>
0xB1D22A 11653674 2 %>
0xB25A0A 11688458 2 %>
$tagasp_short1
43×
Offset (hex) Offset (dec) Length Matched Data
0x21843A 2196538 3 <%\x0F
0x2B9577 2856311 3 <%\x0F
0x2BA4B8 2860216 3 <%\x8D
0x2BA8C8 2861256 3 <%\x0F
0x2BB849 2865225 3 <%\x8B
0x3815F3 3675635 3 <%u
0x3820CA 3678410 3 <%\x0F
0x47C1DD 4702685 3 <%\x00
0x5573D7 5600215 3 <%\x00
0x6C61AB 7102891 3 <%\x0F
0x77B988 7846280 3 <%\x0F
0x77C8B9 7850169 3 <%\x8D
0x77CCC9 7851209 3 <%\x0F
0x77DC4A 7855178 3 <%\x8B
0x842934 8661300 3 <%u
0x84340B 8664075 3 <%\x0F
0x8F3AD2 9386706 3 <%s
0x9206E1 9570017 3 <%2
0x927E61 9600609 3 <%\x97
0xA537DC 10827740 3 <%<
0xA56D72 10841458 3 <%<
0xA58212 10846738 3 <%<
0xA5859E 10847646 3 <%<
0xA58658 10847832 3 <%>
0xA59A34 10852916 3 <%=
0xA5CBB8 10865592 3 <%<
0xA5DE3E 10870334 3 <%<
0xA5EA1E 10873374 3 <%=
0xA5EC94 10874004 3 <%<
0xA65A24 10902052 3 <%<
0xA6B720 10925856 3 <%<
0xA6D128 10932520 3 <%=
0xA6EE3C 10939964 3 <%<
0xA71236 10949174 3 <%=
0xA713E8 10949608 3 <%=
0xB087E7 11569127 3 <%=
0xB0D349 11588425 3 <%=
0xB0E12B 11591979 3 <%<
0xB11B75 11606901 3 <%=
0xB12675 11609717 3 <%<
0xB14BF7 11619319 3 <%<
0xB171D1 11629009 3 <%<
0xB1DF5F 11657055 3 <%=

Matches rule WEBSHELL_ASP_Writer

163×

Matched Strings

$sus1
Offset (hex) Offset (dec) Length Matched Data
0x983AB7 9976503 8 password
$tagasp_short2
24×
Offset (hex) Offset (dec) Length Matched Data
0x5B367 373607 2 %>
0x3ED10F 4116751 2 %>
0x410EC1 4263617 2 %>
0x411C39 4267065 2 %>
0x92489A 9586842 2 %>
0x957990 9795984 2 %>
0x9A3222 10105378 2 %>
0x9A3F9A 10108826 2 %>
0xA53B3D 10828605 2 %>
0xA58659 10847833 2 %>
0xA590BD 10850493 2 %>
0xA5C32B 10863403 2 %>
0xA62DBF 10890687 2 %>
0xA637C7 10893255 2 %>
0xA7AC6B 10988651 2 %>
0xB0A9C4 11577796 2 %>
0xB10B3A 11602746 2 %>
0xB1293C 11610428 2 %>
0xB138CE 11614414 2 %>
0xB14D24 11619620 2 %>
0xB19FFE 11640830 2 %>
0xB1C02C 11649068 2 %>
0xB1D22A 11653674 2 %>
0xB25A0A 11688458 2 %>
$php2
Offset (hex) Offset (dec) Length Matched Data
0xA538BE 10827966 3 <?=
0xA68D54 10915156 3 <?=
0xA6CB4C 10931020 3 <?=
0xB08C89 11570313 3 <?=
0xB1AD59 11644249 3 <?=
$jsp4
34×
Offset (hex) Offset (dec) Length Matched Data
0x39DF34 3792692 6 public
0x39FA30 3799600 12 p\x00u\x00b\x00l\x00i\x00c\x00
0x3CC141 3981633 6 public
0x3CC1D3 3981779 6 public
0x3CC2DB 3982043 6 public
0x3CC3C2 3982274 6 public
0x3CC77C 3983228 6 public
0x3CC8E3 3983587 6 public
0x3CC946 3983686 6 public
0x3CCA26 3983910 6 public
0x3CCA6C 3983980 6 public
0x3CCAD3 3984083 6 public
0x3CCAF8 3984120 6 public
0x3CCB5C 3984220 6 public
0x3CCC37 3984439 6 public
0x3CCCB7 3984567 6 public
0x3CCCF8 3984632 6 public
0x8D19C5 9247173 6 public
0x8D34C1 9254081 12 p\x00u\x00b\x00l\x00i\x00c\x00
0x90A47E 9479294 6 public
0x90A510 9479440 6 public
0x90A61C 9479708 6 public
0x90A703 9479939 6 public
0x90AABD 9480893 6 public
0x90AC24 9481252 6 public
0x90AC87 9481351 6 public
0x90AD67 9481575 6 public
0x90ADAD 9481645 6 public
0x90AE14 9481748 6 public
0x90AE39 9481785 6 public
0x90AE9D 9481885 6 public
0x90B008 9482248 6 public
0x90B088 9482376 6 public
0x90B0C9 9482441 6 public
$asp_input1
21×
Offset (hex) Offset (dec) Length Matched Data
0x3A822F 3834415 7 request
0x3A824D 3834445 7 request
0x3A8649 3835465 7 request
0x3B1280 3871360 7 request
0x3CD5DB 3986907 7 request
0x3CD645 3987013 7 Request
0x40A93B 4237627 7 request
0x40AA88 4237960 7 request
0x40AAA8 4237992 7 request
0x40AB40 4238144 7 request
0x8DE9B9 9300409 7 request
0x8DE9D7 9300439 7 request
0x8DEEB6 9301686 7 request
0x8ECA8E 9357966 7 request
0x937360 9663328 7 request
0x9373CA 9663434 7 Request
0x999AF7 10066679 7 request
0x99CC9C 10079388 7 request
0x99CDE9 10079721 7 request
0x99CE09 10079753 7 request
0x99CEA1 10079905 7 request
$asp_xml_method1
Offset (hex) Offset (dec) Length Matched Data
0x3AE714 3860244 6 G\x00E\x00T\x00
0x3AE9A2 3860898 6 G\x00E\x00T\x00
0x40A920 4237600 6 G\x00E\x00T\x00
0x8E5C33 9329715 6 G\x00E\x00T\x00
0x8E5C4F 9329743 6 G\x00E\x00T\x00
0x99CC81 10079361 6 G\x00E\x00T\x00
$asp_xml_method2
Offset (hex) Offset (dec) Length Matched Data
0x40A90E 4237582 8 P\x00O\x00S\x00T\x00
0x8F36A4 9385636 4 POST
0x97800C 9928716 4 POST
0x99CC6D 10079341 8 P\x00O\x00S\x00T\x00
$asp_xml_method3
Offset (hex) Offset (dec) Length Matched Data
0x9772DD 9925341 4 HEAD
$asp_form1
Offset (hex) Offset (dec) Length Matched Data
0x9839E5 9976293 6 <form
0x988C61 9997409 6 <form
0x98D617 10016279 6 <form
0x98DEE5 10018533 6 <form
0x98F327 10023719 6 <form
0x993725 10041125 6 <form
$asp_text1
Offset (hex) Offset (dec) Length Matched Data
0x170 368 5 .text
0x3BF11A 3928346 5 .text
0x4269D1 4352465 5 .text
0x8FA3BB 9413563 5 .text
0x9937E1 10041313 5 .text
$tagasp_short1
43×
Offset (hex) Offset (dec) Length Matched Data
0x21843A 2196538 3 <%\x0F
0x2B9577 2856311 3 <%\x0F
0x2BA4B8 2860216 3 <%\x8D
0x2BA8C8 2861256 3 <%\x0F
0x2BB849 2865225 3 <%\x8B
0x3815F3 3675635 3 <%u
0x3820CA 3678410 3 <%\x0F
0x47C1DD 4702685 3 <%\x00
0x5573D7 5600215 3 <%\x00
0x6C61AB 7102891 3 <%\x0F
0x77B988 7846280 3 <%\x0F
0x77C8B9 7850169 3 <%\x8D
0x77CCC9 7851209 3 <%\x0F
0x77DC4A 7855178 3 <%\x8B
0x842934 8661300 3 <%u
0x84340B 8664075 3 <%\x0F
0x8F3AD2 9386706 3 <%s
0x9206E1 9570017 3 <%2
0x927E61 9600609 3 <%\x97
0xA537DC 10827740 3 <%<
0xA56D72 10841458 3 <%<
0xA58212 10846738 3 <%<
0xA5859E 10847646 3 <%<
0xA58658 10847832 3 <%>
0xA59A34 10852916 3 <%=
0xA5CBB8 10865592 3 <%<
0xA5DE3E 10870334 3 <%<
0xA5EA1E 10873374 3 <%=
0xA5EC94 10874004 3 <%<
0xA65A24 10902052 3 <%<
0xA6B720 10925856 3 <%<
0xA6D128 10932520 3 <%=
0xA6EE3C 10939964 3 <%<
0xA71236 10949174 3 <%=
0xA713E8 10949608 3 <%=
0xB087E7 11569127 3 <%=
0xB0D349 11588425 3 <%=
0xB0E12B 11591979 3 <%<
0xB11B75 11606901 3 <%=
0xB12675 11609717 3 <%<
0xB14BF7 11619319 3 <%<
0xB171D1 11629009 3 <%<
0xB1DF5F 11657055 3 <%=
$asp_always_write1
13×
Offset (hex) Offset (dec) Length Matched Data
0x3B95C9 3904969 6 .Write
0x3C5621 3954209 6 .Write
0x8F1C1D 9378845 6 .Write
0x8F1C8F 9378959 6 .Write
0x8F1CAD 9378989 6 .Write
0x8F1CD9 9379033 6 .Write
0x8F464A 9389642 6 .Write
0x900C12 9440274 6 .Write
0x98F230 10023472 6 .write
0x990262 10027618 6 .write
0x990AD9 10029785 6 .write
0x99242D 10036269 6 .write
0x995F07 10051335 6 .Write

Matches rule WEBSHELL_PHP_OBFUSC

57×

Matched Strings

$php_short
50×
Offset (hex) Offset (dec) Length Matched Data
0x5F056 389206 2 <?
0x5F0ED 389357 2 <?
0xDF011 913425 2 <?
0x1752B5 1528501 2 <?
0x1ACFC6 1757126 2 <?
0x1AD0D2 1757394 2 <?
0x1AD730 1759024 2 <?
0x1AD7DC 1759196 2 <?
0x1ADA56 1759830 2 <?
0x1ADAF2 1759986 2 <?
0x1B1BA3 1776547 2 <?
0x213ECC 2178764 2 <?
0x213F1B 2178843 2 <?
0x213FEF 2179055 2 <?
0x21402E 2179118 2 <?
0x2140EC 2179308 2 <?
0x2141CB 2179531 2 <?
0x22ABC0 2272192 2 <?
0x23C9FF 2345471 2 <?
0x23DC4A 2350154 2 <?
0x23ECE3 2354403 2 <?
0x2400D7 2359511 2 <?
0x378C61 3640417 2 <?
0x378CA2 3640482 2 <?
0x378CC8 3640520 2 <?
0x38ABFF 3714047 2 <?
0x38AC9B 3714203 2 <?
0x38B41A 3716122 2 <?
0x38B49C 3716252 2 <?
0x3D0EE0 4001504 2 <?
0x410A8F 4262543 2 <?
0x51274C 5318476 2 <?
0x512CA9 5319849 2 <?
0x54F9A2 5568930 2 <?
0x5CB721 6076193 2 <?
0x5CB72F 6076207 2 <?
0x5FD236 6279734 2 <?
0x654A76 6638198 2 <?
0x654B8D 6638477 2 <?
0x654DB7 6639031 2 <?
0x654EC3 6639299 2 <?
0x655521 6640929 2 <?
0x6555CD 6641101 2 <?
0x655847 6641735 2 <?
0x6558E3 6641891 2 <?
0x659994 6658452 2 <?
0x6C1C3D 7085117 2 <?
0x6C1C8C 7085196 2 <?
0x6C1D60 7085408 2 <?
0x6C1D9F 7085471 2 <?
$no_xml1
Offset (hex) Offset (dec) Length Matched Data
0xA52CA1 10824865 13 <?xml version
0xB07510 11564304 13 <?xml version
$php_new1
Offset (hex) Offset (dec) Length Matched Data
0xA538BE 10827966 4 <?=\x99
0xA68D54 10915156 4 <?=i
0xA6CB4C 10931020 4 <?=l
0xB08C89 11570313 4 <?=b
0xB1AD59 11644249 4 <?=

Matches rule WEBSHELL_PHP_OBFUSC_Tiny

57×

Matched Strings

$php_short
50×
Offset (hex) Offset (dec) Length Matched Data
0x5F056 389206 2 <?
0x5F0ED 389357 2 <?
0xDF011 913425 2 <?
0x1752B5 1528501 2 <?
0x1ACFC6 1757126 2 <?
0x1AD0D2 1757394 2 <?
0x1AD730 1759024 2 <?
0x1AD7DC 1759196 2 <?
0x1ADA56 1759830 2 <?
0x1ADAF2 1759986 2 <?
0x1B1BA3 1776547 2 <?
0x213ECC 2178764 2 <?
0x213F1B 2178843 2 <?
0x213FEF 2179055 2 <?
0x21402E 2179118 2 <?
0x2140EC 2179308 2 <?
0x2141CB 2179531 2 <?
0x22ABC0 2272192 2 <?
0x23C9FF 2345471 2 <?
0x23DC4A 2350154 2 <?
0x23ECE3 2354403 2 <?
0x2400D7 2359511 2 <?
0x378C61 3640417 2 <?
0x378CA2 3640482 2 <?
0x378CC8 3640520 2 <?
0x38ABFF 3714047 2 <?
0x38AC9B 3714203 2 <?
0x38B41A 3716122 2 <?
0x38B49C 3716252 2 <?
0x3D0EE0 4001504 2 <?
0x410A8F 4262543 2 <?
0x51274C 5318476 2 <?
0x512CA9 5319849 2 <?
0x54F9A2 5568930 2 <?
0x5CB721 6076193 2 <?
0x5CB72F 6076207 2 <?
0x5FD236 6279734 2 <?
0x654A76 6638198 2 <?
0x654B8D 6638477 2 <?
0x654DB7 6639031 2 <?
0x654EC3 6639299 2 <?
0x655521 6640929 2 <?
0x6555CD 6641101 2 <?
0x655847 6641735 2 <?
0x6558E3 6641891 2 <?
0x659994 6658452 2 <?
0x6C1C3D 7085117 2 <?
0x6C1C8C 7085196 2 <?
0x6C1D60 7085408 2 <?
0x6C1D9F 7085471 2 <?
$no_xml1
Offset (hex) Offset (dec) Length Matched Data
0xA52CA1 10824865 13 <?xml version
0xB07510 11564304 13 <?xml version
$php_new1
Offset (hex) Offset (dec) Length Matched Data
0xA538BE 10827966 4 <?=\x99
0xA68D54 10915156 4 <?=i
0xA6CB4C 10931020 4 <?=l
0xB08C89 11570313 4 <?=b
0xB1AD59 11644249 4 <?=

Matches rule WebShell_php_webshells_MyShell

50×

Matched Strings

$s14
50×
Offset (hex) Offset (dec) Length Matched Data
0x194 404 1
0x284 644 1
0xBA1 2977 1
0xBD2 3026 1
0xBDB 3035 1
0xC04 3076 1
0xC08 3080 1
0xC1F 3103 1
0xC4E 3150 1
0xC52 3154 1
0xC7F 3199 1
0xC88 3208 1
0xCB5 3253 1
0xCB9 3257 1
0xCC9 3273 1
0xCEB 3307 1
0xD33 3379 1
0xD3A 3386 1
0x1544 5444 1
0x17DC 6108 1
0x182D 6189 1
0x1830 6192 1
0x18E3 6371 1
0x196F 6511 1
0x1987 6535 1
0x1A83 6787 1
0x1B48 6984 1
0x1BF1 7153 1
0x1C7F 7295 1
0x1D9A 7578 1
0x21B3 8627 1
0x23E7 9191 1
0x2518 9496 1
0x25F6 9718 1
0x27C0 10176 1
0x294A 10570 1
0x2B7E 11134 1
0x2CAF 11439 1
0x2D8D 11661 1
0x2F57 12119 1
0x2FF8 12280 1
0x3081 12417 1
0x3233 12851 1
0x32E3 13027 1
0x33C1 13249 1
0x3509 13577 1
0x3589 13705 1
0x3612 13842 1
0x37C8 14280 1
0x387D 14461 1

Matches rule aspydrv_asp

Matched Strings

$s1
Offset (hex) Offset (dec) Length Matched Data
0x3BF46C 3929196 8 password
0x8FA70D 9414413 8 password
0x9031A7 9449895 8 password
0x97F551 9958737 8 password
0x983AB7 9976503 8 password

Matches rule explorer_ANOMALY

Matched Strings

$s1
Offset (hex) Offset (dec) Length Matched Data
0x3B6870 3893360 24 E\x00X\x00P\x00L\x00O\x00R\x00E\x00R\x00.\x00E\x00X\x00E\x00
0x8E976D 9344877 24 E\x00X\x00P\x00L\x00O\x00R\x00E\x00R\x00.\x00E\x00X\x00E\x00

Matches rule gen_exploit_CVE_2017_10271_WebLogic from malware by John Lambert @JohnLaTwC

Exploit for CVE-2017-10271 (Oracle WebLogic)

HIGHVOL
AuthorJohn Lambert @JohnLaTwC

Matched Strings

$s3
Offset (hex) Offset (dec) Length Matched Data
0x39DE34 3792436 4 void
0x39DF88 3792776 4 void
0x8D18C5 9246917 4 void
0x8D1A19 9247257 4 void
0x9930A8 10039464 4 void
$s4
Offset (hex) Offset (dec) Length Matched Data
0x985554 9983316 6 index=
0x986B6C 9988972 6 index=
0x988FD2 9998290 6 index=
0xB25C0A 11688970 6 index=
rule gen_exploit_CVE_2017_10271_WebLogic : HIGHVOL
{
    meta: 
        description = "Exploit for CVE-2017-10271 (Oracle WebLogic)"
        author = "John Lambert @JohnLaTwC"
        date = "2018-03-21"
        hash1 = "376c2bc11d4c366ad4f6fecffc0bea8b195e680b4c52a48d85a8d3f9fab01c95"
        hash2 = "7d5819a2ea62376e24f0dd3cf5466d97bbbf4f5f730eb9302307154b363967ea"
        hash3 = "864e9d8904941fae90ddd10eb03d998f85707dc2faff80cba2e365a64e830e1d/subfile"
        hash4 = "2a69e46094d0fef2b3ffcab73086c16a10b517f58e0c1f743ece4f246889962b"
        reference = "https://github.com/c0mmand3rOpSec/CVE-2017-10271, https://www.fireeye.com/blog/threat-research/2018/02/cve-2017-10271-used-to-deliver-cryptominers.html"
        id = "e30e316f-1ebb-5c38-ba25-d2a9d0083a03"
    strings:
        $s1 = "<soapenv:Header"
        $s2 = "java.beans.XMLDecoder"
        $s3 = "void" fullword
        $s4 = "index="
        $s5 = "/array>"
        $s6 = "\"start\""
        $s7 = "work:WorkCont}

Matches rule gen_python_pyminifier_encoded_payload from malware by John Lambert @JohnLaTwC

Detects python code encoded by pyminifier. Used by the Machete malware as researched by ESET

AuthorJohn Lambert @JohnLaTwC

Matched Strings

$s3
Offset (hex) Offset (dec) Length Matched Data
0x40A3FE 4236286 4 zlib
0x40A68A 4236938 4 zlib
0x9994FF 10065151 4 zlib
0x99978B 10065803 4 zlib
rule gen_python_pyminifier_encoded_payload
{
    meta:
        description = "Detects python code encoded by pyminifier. Used by the Machete malware as researched by ESET"
        author = "John Lambert @JohnLaTwC"
        date = "2019-12-16"
        reference = "https://www.welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete.pdf"
        reference2 = "https://github.com/liftoff/pyminifier"
        hash = "01df8765ea35db382d1dd67a502bf1d9647d8fe818ec31abff41c7e41c2816c0"
        hash = "15d201152a9465497a0f9dd6939e48315b358702c5e2a3c506ad436bb8816da7"
        hash = "ab91f76394ddf866cc0b315d862a19b57ded93be5dfc2dd0a81e6a43d0c5f301"
        hash = "b67256906d976aafb6071d23d1b3f59a1696f26b25ff4713b9342d41e656dfba"
        hash = "d5664c70f3543f306f765ea35e22829dbea66aec729e8e11edea9806d0255b7e"
        hash = "dd2b0e2c2cb8a83574248bda54ce472899b22eb602e8ebecafcce2c4355177fe"
        hash = "ed76bd136f40a23aeffe0aba02f13b9fea3428c19b715aafa6ea9be91e4006ca"

        hash = "b454179c13cb4727ae06cc9cd126c3379e2aded5c293af0234ac3312bf9bdad2"

        id = "d7297e6a-e1c7-57dd-a57f-a3b67face2f3"
    strings:
        $s1 = "exec(zlib.decompress(base64.b64decode('eJ"
        $s2 = "base64" fullword
        $s3 = "zlib" fullword

 }

Matches rule svchost_ANOMALY from malware

Abnormal svchost.exe - typical strings not found in file

Matched Strings

$win2003_win7_u2
Offset (hex) Offset (dec) Length Matched Data
0x3AB21A 3846682 34 I\x00n\x00t\x00e\x00r\x00n\x00e\x00t\x00 \x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00
0x3C25D2 3941842 34 I\x00n\x00t\x00e\x00r\x00n\x00e\x00t\x00 \x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00
0x8E1C6D 9313389 34 I\x00n\x00t\x00e\x00r\x00n\x00e\x00t\x00 \x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00
0x8FD9F3 9427443 34 I\x00n\x00t\x00e\x00r\x00n\x00e\x00t\x00 \x00E\x00x\x00p\x00l\x00o\x00r\x00e\x00r\x00
$win2003_win7_u3
Offset (hex) Offset (dec) Length Matched Data
0x9D3E07 10305031 22 T\x00r\x00a\x00n\x00s\x00l\x00a\x00t\x00i\x00o\x00n\x00
0xB074F2 11564274 22 T\x00r\x00a\x00n\x00s\x00l\x00a\x00t\x00i\x00o\x00n\x00
$win2003_win7_u4
Offset (hex) Offset (dec) Length Matched Data
0x9D3DE7 10304999 22 V\x00a\x00r\x00F\x00i\x00l\x00e\x00I\x00n\x00f\x00o\x00
0xB074D2 11564242 22 V\x00a\x00r\x00F\x00i\x00l\x00e\x00I\x00n\x00f\x00o\x00
rule svchost_ANOMALY
{4/2014"
      score = 55
      nodeepdive = 1
      id = "ea436608-d191-5058-b844-025e48082edc"
   strings:
      $win2003_win7_u1 = "IEXPLORE.EXE" wide nocase
      $win2003_win7_u2 = "Internet Explorer" wide fullword
      $win2003_win7_u3 = "translation" wide fullword nocase
      $win2003_win7_u4 = "varfileinfo" wide fullword nocase
   condition:
      filename == "iexplore.exe"
      and uint16(0) == 0x5a4d
      and not filepath contains "teamviewer"
      and not 1 of ($win*) and not WINDOWS_UPDATE_BDC
      and filepath contains "C:\\"
      and not filepath contains "Package_for_RollupFix"
}

rule svchost_ANOMALY {
	meta:
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		description = "Abnormal svchost.exe - typical strings not found in file"
		date = "23/04/2014"
		score = 55
		id = "5630054d-9fa4-587f-ba78-cda4478f9cc1"
	strings:
		$win2003_win7_u1 = "svchost.exe" wide nocase
		$win2003_win7_u3 = "coinitializesecurityparam" wide fullword nocase
		$win2003_win7_u4 = "servicedllunloadonstop" wide fullword nocase
		$win2000 = "Generic Host Process for Win32 Services" wide fullword
		$win2012 = "Host Process for Windows Serv}

Hashes

SHA-256

b350eae6c630a1d2340703a6d01a6031b2c98941b50bd826732fca4ca792da24

SHA-1

0391327852ea0151812d220f3d2741d3964a9e0a

MD5

30f1d8e1d628362b06c2b6d3f6d6c1bf

SHA-512

a94ee63a3a2894c999e7f6a77578c5d609369bc4ec21e166a6852e29887c96d826132634cbe29628b4c1cdc29eaa4780ab87c0386d63d8feb6be6b2a0616fad0

File Properties

Detected Type Windows Executable (PE)
Magic PE32 executable for MS Windows 10.00 (GUI), Intel i386, 9 sections
Client MIME application/vnd.microsoft.portable-executable
Size 11.2 MB
Entropy 6.778 / 8.0
Times Analyzed 4
First Analyzed Aug 9, 2026 06:05
Last Analyzed Aug 9, 2026 18:10

Executable (PE) Details

Machine x86 (32-bit)
Bitness 32-bit (PE32)
Subsystem Windows GUI
Compiled 2026-04-28 14:04:34 UTC
Entry Point 0x2200B0
Type EXE
Imphash 293db4c91ca6a5fb5da24453e6831a72
Imported DLLs 17
Imported Functions 159
Exported Functions 1
Digitally signed
Section Virtual Size Raw Size Entropy
.text 3778614 3779072 6.69
.rdata 529792 529920 6.02
.data 189020 22016 3.68
.fptable 128 512 0.00
.tls 449 512 0.38
CPADinfo 40 512 0.12
malloc_h 789 1024 5.42
.rsrc 7230692 7230976 6.76
.reloc 114160 114176 6.75
Imported DLLs (17)
ADVAPI32.dll — 25 function(s)
dbghelp.dll — 8 function(s)
GDI32.dll — 8 function(s)
OLEAUT32.dll — 15 function(s)
SHELL32.dll — 5 function(s)
SHLWAPI.dll — 2 function(s)
USER32.dll — 25 function(s)
WINMM.dll — 3 function(s)
KERNEL32.dll — 25 function(s)
ole32.dll — 14 function(s)
ntdll.dll — 4 function(s)
USERENV.dll — 4 function(s)
Secur32.dll — 1 function(s)
WTSAPI32.dll — 3 function(s)
api-ms-win-core-winrt-l1-1-0.dll — 2 function(s)
WINHTTP.dll — 12 function(s)
api-ms-win-core-synch-l1-2-0.dll — 3 function(s)

No IP addresses, domains, or URLs were found in this file's extracted strings.

Static Strings

500 strings · printable ASCII ≥ 6 chars
Offset (hex) Offset (dec) String
0x4D 77 !This program cannot be run in DOS mode.$
0x197 407 `.rdata
0x1BF 447 @.data
0x1E8 488 .fptable
0x238 568 CPADinfo(
0x260 608 malloc_h
0x287 647 `.rsrc
0x2AF 687 @.reloc
0x5EC 1516 )QZ^&1
0xD54 3412 Montgomery Multiplication for x86, CRYPTOGAMS by <appro@openssl.org>
0xF3E 3902 *p[[[[[[[[[[[[[[[[
0x10D0 4304 Vector Permutation AES for x86/SSSE3, Mike Hamburg (Stanford University)
0x1886 6278 d$0_^[]
0x18C6 6342 d$0_^[]
0x3B8D 15245 D7q/;M
0x3E10 15888 SHA512 block transform for x86, CRYPTOGAMS by <appro@openssl.org>
0x4250 16976 SHA256 block transform for x86, CRYPTOGAMS by <appro@openssl.org>
0x62E3 25315 d$l_^[]
0x716C 29036 d$l_^[]
0xAD60 44384 SHA1 block transform for x86, CRYPTOGAMS by <appro@openssl.org>
0xB2E0 45792 GHASH for x86, CRYPTOGAMS by <appro@openssl.org>
0xBC07 48135 X<[]_^
0xC06B 49259 _<[]_^
0xD622 54818 d$P_^[]
0xDBB5 56245 d$t_^[]
0xE1A8 57768 d$t_^[]
0xEBC0 60352 AES for Intel AES-NI, CRYPTOGAMS by <appro@openssl.org>
0xF094 61588 3K 3s$3S03{8
0xF126 61734 3K(3s,3S43{<
0xFC60 64608 expand 32-byte k
0xFCC0 64704 ChaCha20 for x86, CRYPTOGAMS by <appro@openssl.org>
0x10D41 68929 ffffff.
0x10D62 68962 fffff.
0x11E81 73345 ffffff.
0x12032 73778 fffff.
0x13A49 80457 VShpVe
0x13C19 80921 VShpVe
0x169D4 92628 D$$j%h
0x16A26 92710 D$$j,h
0x16B4C 93004 w jFh[
0x16EC7 93895 uojFh[
0x16FB0 94128 D$Hj3hc
0x171A3 94627 D$Hj$h
0x19AA6 105126 RWRRRPh
0x19ADE 105182 RWRRRPh
0x1D518 120088 WRRRPh
0x1D551 120145 WRRRPh
0x1E2A7 123559 L$XWj3h
0x1E533 124211 t$DjTh
0x1F0FF 127231 D$xj'h
0x2291B 141595 ID;NHs
0x22A2E 141870 F@;FDtM
0x237BA 145338 F(:G(uw
0x23CD4 146644 D$/NOWN
0x23CDC 146652 D$,UNKN
0x23D75 146805 D$/CESS
0x23D7D 146813 D$,SUCC
0x23DAD 146861 D$0TIVE
0x23DB5 146869 D$,INAC
0x25703 153347 T$0VQPR
0x25AA8 154280 |$dRRRh
0x28630 165424 O$VPQW
0x2DFED 188397 ucj0h_
0x2E7F2 190450 |$0Vhi
0x316BF 202431 t$,QPV
0x39805 235525 u{j'h+
0x39833 235571 D$<j1h
0x3D5BC 251324 D$\yMod
0x3D5C4 251332 D$XProxf
0x3E4DA 255194 D$\yMod
0x3E4E2 255202 D$XProxf
0x3F96B 260459 uQj'h+
0x3FBAC 261036 uej'h+
0x3FDBF 261567 u[j'h+
0x44C3A 281658 L$ SPR
0x473D3 291795 )D$ WV
0x474B5 292021 D$(j(h6
0x4A74A 304970 }8j1hL
0x4E0B1 319665 L$@;D$0
0x4E19A 319898 L$@;D$0
0x4E21B 320027 L$@;D$0
0x4E2C6 320198 L$@;D$0
0x4E35E 320350 |$ Vh,
0x4E3D2 320466 L$@;D$0
0x4E494 320660 L$@;D$0
0x4E57F 320895 L$@;D$0
0x4E67D 321149 L$@;D$0
0x4E6D0 321232 D$,+D$(
0x4E7F8 321528 t$,+t$(
0x4EB6E 322414 ;G t~;G
0x55903 350467 SQRPWV
0x5C40D 377869 PRSSPRQ
0x61488 398472 uIj+h@
0x63D87 408967 ucj+h@
0x666C6 419526 SVhpVe
0x68C40 429120 f9F&r]u4
0x6B5A0 439712 D$,PhH
0x70872 460914 )D$ j
0x72A8E 469646 KI5.(
0x72B87 469895 KI5.(
0x77366 488294 D$Ltq1
0x7846F 492655 KI5.(
0x78518 492824 KI5.(
0x78BFC 494588 WQQQRPS
0x7A035 499765 T$ PQR
0x7AEEF 503535 SPRWPR
0x7B068 503912 T$0PQR
0x84509 541961 L$ PQh
0x84B95 543637 N ;N$s/
0x85281 545409 ^@jOPQS
0x86AEC 551660 T$Pr&j
0x86B28 551720 D$ ;D$$
0x96766 616294 t$(jNh
0x9A3B7 631735 j@SRWQj
0x9D569 644457 @;D$0u
0x9D947 645447 ;D$ tJ
0x9D952 645458 @;D$ u
0x9DD90 646544 \$0+\$
0x9E3F3 648179 PVSWPP
0xA11A1 659873 L$DQSh
0xA1250 660048 QQWVPSQ
0xA3651 669265 VWh<#{
0xA3BC7 670663 VWh<#{
0xA3F05 671493 r49q tu
0xA4174 672116 tG97uC
0xA45CB 673227 4Cf94Aw(r
0xA4C5E 674910 VWSRPQ
0xA5784 677764 N$^_[]
0xA58D2 678098 N$^_[]
0xA59B9 678329 N$^_[]
0xA5ADE 678622 N$^_[]
0xA5D58 679256 N$^_[]
0xA6C3A 683066 N$^_[]
0xA7134 684340 N$^_[]
0xABEC2 704194 fffff.
0xABF02 704258 fffff.
0xABF42 704322 fffff.
0xABFA2 704418 fffff.
0xAC002 704514 fffff.
0xAC042 704578 fffff.
0xAC082 704642 fffff.
0xAC0C2 704706 fffff.
0xAC102 704770 fffff.
0xAC142 704834 fffff.
0xAC182 704898 fffff.
0xAC1C2 704962 fffff.
0xAC202 705026 fffff.
0xAC242 705090 fffff.
0xAC282 705154 fffff.
0xAC2C2 705218 fffff.
0xAC302 705282 fffff.
0xAC342 705346 fffff.
0xAC382 705410 fffff.
0xAC3C2 705474 fffff.
0xAC402 705538 fffff.
0xAC442 705602 fffff.
0xAC482 705666 fffff.
0xAC4C2 705730 fffff.
0xAC502 705794 fffff.
0xAC562 705890 fffff.
0xAC5A2 705954 fffff.
0xAC5E2 706018 fffff.
0xAC622 706082 fffff.
0xAC662 706146 fffff.
0xAF0AC 716972 j hf&|
0xAF0EC 717036 j h{&|
0xAF7C8 718792 t5jLSW
0xB0A63 723555 VWPSRQ
0xB0C12 723986 VWPSRQ
0xB17F8 727032 WRSRRRQP
0xB1847 727111 QRPSPPPW
0xB456E 738670 j h}+|
0xB4D6C 740716 D$0PRQ
0xB4F16 741142 L$ QPj
0xB511C 741660 L$PPQRW
0xB58F9 743673 WQVVWQP
0xB62E7 746215 QQRSWP
0xB69AE 747950 PWQVVRV
0xB6B58 748376 L$PPVQ
0xB6BA4 748452 L$PPhP.|
0xB6D27 748839 QWSPPRP
0xB7237 750135 j=h+/|
0xB748F 750735 j&hi/|
0xBACA5 765093 :^,v>1
0xBB16F 766319 jDht2|
0xBB1C0 766400 QSQWQP
0xBB503 767235 SVh-3|
0xBBD91 769425 t$ j$h04|
0xBBEEF 769775 L$ PPW
0xBC033 770099 Rj8QRP
0xBD985 776581 L$$;L$(
0xBDA41 776769 L$$;L$(
0xBDB78 777080 PPj WS
0xBEA20 780832 T$,RQSh
0xBEA81 780929 L$ Qj(Vj
0xBEB54 781140 L$ QVSWWhH
0xBFFCD 786381 t$ jMh69|
0xC083A 788538 A0unkn
0xC1B3E 793406 j4hm:|
0xC6BE6 814054 t7;~8u;
0xC8CD4 822484 L$)WQP
0xCBAE3 834275 u0^_[]
0xCC4C4 836804 D$ph8I|
0xCC50E 836878 D$hhhI|
0xCD6E8 841448 D$P+G8
0xD1B49 858953 ^4;^8s
0xD1F1A 859930 ;F u!W
0xD4986 870790 Fl;Fpu6
0xD49DD 870877 Fl;Fpt%
0xD5418 873496 Fl;Fpu
0xD738C 881548 x+^_[]
0xD74F6 881910 Y`WVRP
0xD7AE1 883425 D$XtT|
0xD7C36 883766 D$XzT|
0xD8754 886612 L$)WQP
0xD89C8 887240 6RWQVP
0xD9098 888984 t-^_[]
0xD98CE 891086 VRRjNh
0xD9E72 892530 VRRjDh
0xDD953 907603 ud^_[]
0xE52D8 938712 6RWQVP
0xE6A83 944771 T$LRPW
0xE7A6E 948846 O ;O$r!
0xE7BB6 949174 N ;N$r
0xE963A 955962 D$8Ui|
0xEAA6D 961133 t$Phtg|
0xEAB53 961363 \$pj VS
0xEB50F 963855 |$@QVW
0xECEFF 970495 8WWPWVWh
0xED09B 970907 Qj-h1q|
0xEF58E 980366 4Qf;tS
0xF35E6 996838 8RSDSuW
0xF4B8C 1002380 s(^_[]
0xFC8BC 1034428 D$,)D$
0xFC8C4 1034436 D$L)D$
0xFC8CC 1034444 D$H)D$
0xFC8D4 1034452 D$D)D$(
0xFC8DC 1034460 D$@)D$$+|$<
0xFC8E8 1034472 D$8)D$ +L$4
0x102EAB 1060523 G/0C/j
0x105A08 1071624 )L$0u2
0x1066F3 1074931 D$(VWP
0x106923 1075491 ;<$|19
0x108E67 1085031 G<;G@u
0x109730 1087280 G<;G@u
0x10C6D1 1099473 N4^_[]
0x1105C3 1115587 F8^_[]
0x11125A 1118810 L$(PQj
0x1115FA 1119738 $B;T$(
0x111DBE 1121726 8PhP+Q
0x11BE12 1162770 ^|9Z|t'
0x11D7DB 1169371 A$:G$u
0x11F882 1177730 WPPRPRR
0x12167B 1185403 N@j[h)
0x122349 1188681 WSh 8R
0x1223B1 1188785 WSh 8R
0x1232FC 1192700 PPWPWW
0x12346E 1193070 D$,8D$+y
0x123ACF 1194703 D$,;D$0u
0x123B20 1194784 D$,;D$0u
0x123B75 1194869 D$,;D$0u
0x123C03 1195011 D$,;D$0u
0x123C91 1195153 D$,;D$0u
0x123CC4 1195204 T$,RQP
0x123D19 1195289 D$,;D$0u
0x123D4C 1195340 T$,RQP
0x123DA1 1195425 D$,;D$0u
0x123DD0 1195472 T$,RQP
0x126F5C 1208156 WWj h-
0x126F6C 1208172 WWj(hN
0x126F7C 1208188 WWj*hw
0x12842D 1213485 |$ PRW
0x12D409 1233929 ;D$ u]
0x12D95E 1235294 WPSSWPQ
0x12E125 1237285 t$$#t$(
0x12E131 1237297 t$4#t$,
0x12E15F 1237343 t$,#t$8xX
0x12E16C 1237356 |$$#|$(
0x12E178 1237368 T$<#T$(
0x12E3B4 1237940 t$ #D$,#|$4
0x12E4E7 1238247 !T$4!\$,
0x130B8C 1248140 tD^_[]
0x1326B4 1255092 T$ 3t$
0x13660F 1271311 j8hD&{
0x13B9F7 1292791 RVQPVV
0x13F0CF 1306831 u'WVPQR
0x140A37 1313335 ~D^_[]
0x141214 1315348 :t1NG9
0x141AB3 1317555 V8WRPQ
0x141E1B 1318427 T$0WQPR
0x143FB7 1327031 uijNh,
0x144476 1328246 rajNh,
0x144834 1329204 t=jNh,
0x144BB5 1330101 D$8@u@1
0x14F649 1373769 SQQQPW
0x1502E2 1376994 \$(;|$
0x1503F1 1377265 |$0;D$
0x1504E2 1377506 \$$;t$
0x150623 1377827 D$ ;|$
0x150B49 1379145 L$4;|$8u
0x150CB3 1379507 D$4;|$Du
0x1510D4 1380564 |$ ;T$
0x152FB6 1388470 L$8RPQ
0x153B99 1391513 D$0PVWf
0x153DB7 1392055 L$0RPQ
0x154220 1393184 9\$,tb
0x157FD7 1408983 EL$,+T$
0x158144 1409348 |$0+L$
0x1581F6 1409526 \$$+\$@
0x15822D 1409581 |$0;t$
0x158B8E 1411982 T$(9l$ t
0x158C8C 1412236 B9T$ t
0x158CCC 1412300 T$,tW9
0x15E8B4 1435828 PPVQSW
0x163BB2 1457074 fffff.
0x165212 1462802 fffff.
0x168B20 1477408 'ffffff.
0x169751 1480529 pfffff.
0x16AEB9 1486521 D$(WQVSP
0x170BD1 1510353 ffffff.
0x170CB2 1510578 fffff.
0x170CF1 1510641 ffffff.
0x170F96 1511318 t?^_[]
0x171369 1512297 VWhW {
0x1722FF 1516287 H49H0t
0x172342 1516354 VWhU"{
0x17307E 1519742 ks;ffffff.
0x1759C1 1530305 RD;Q s
0x175A78 1530488 RD;Q(s
0x176361 1532769 ffffff.
0x177B32 1538866 4Af94Bw
0x1789F4 1542644 N$^_[]
0x178EF1 1543921 ffffff.
0x1794E1 1545441 L$)VQP
0x17B1D2 1552850 fffff.
0x17B790 1554320 r4fffff.
0x17FC62 1571938 fffff.
0x17FF91 1572753 ffffff.
0x181818 1579032 WWSSRP
0x181BF9 1580025 U RSVW
0x183B43 1588035 VVSSRP
0x1861A2 1597858 D$ W0|
0x1861B0 1597872 T$$RQP
0x1861D5 1597909 T$$RQP
0x1868F9 1599737 t$TPRVQ
0x186D91 1600913 ffffff.
0x18C3F1 1623025 ffffff.
0x18E8D0 1632464 L$H@JG
0x18EC91 1633425 L$<iT$,
0x18F601 1635841 tt{<Suo
0x18F914 1636628 D$d+D$D
0x18F91C 1636636 D$L+D$H
0x18F92F 1636655 D$`+D$
0x18FDA2 1637794 L$ 9t$$
0x190091 1638545 kD$x<iL$|
0x191054 1642580 ~0;~4u
0x196BDF 1666015 D$$9D$,u?
0x196EF0 1666800 G0kO4X
0x196F96 1666966 OD;OHt
0x196FC6 1667014 G8;G<tp;G4sn
0x197160 1667424 C8;C<u7
0x197223 1667619 KD;KHt
0x1972FA 1667834 C8;C<tI;C4sG
0x197389 1667977 GD;GHu
0x198204 1671684 u-958s
0x198249 1671753 j,h$F|
0x1990F2 1675506 L$ PVW
0x19BE19 1687065 L$GRPVW
0x19C553 1688915 WVhiJ|
0x19C560 1688928 N,WVhqJ|
0x19CD11 1690897 D$ 3D$4
0x19CD20 1690912 ;D$,tX
0x19DC22 1694754 D$`;D$@
0x19F44B 1700939 ^PSPQjCh
0x19F9AC 1702316 PRVjCh
0x19FE18 1703448 ^ SPRjCh
0x1A0462 1705058 Fl;Fpt
0x1A0544 1705284 Gl;Gptz
0x1A056A 1705322 _l;_ptk
0x1A0683 1705603 Fl;Fpt*
0x1A1695 1709717 Fl;Fpt
0x1A313C 1716540 \$0QRj
0x1A3174 1716596 \$8SQj
0x1A3711 1718033 \$TWQj
0x1A3749 1718089 \$HSQj
0x1A3C9A 1719450 \$8SQj
0x1A3D96 1719702 t$0VWP
0x1A406C 1720428 t$ +t$
0x1A41FF 1720831 D$ 3D$
0x1A469B 1722011 D$(;D$
0x1A7531 1733937 ffffff.
0x1A75EA 1734122 D$`;D$h
0x1A77C0 1734592 uI^_[]
0x1A79FF 1735167 hMbP?h
0x1A8332 1737522 fffff.
0x1A85BC 1738172 9L$\t"
0x1A866B 1738347 9L$\t"
0x1A8840 1738816 T$PRQW1
0x1A958C 1742220 D$@:[|
0x1A9B35 1743669 D$ ;D$(
0x1AA013 1744915 VRWWVRP
0x1ABA1D 1751581 un^_[]
0x1ABCDB 1752283 un^_[]
0x1AC3AA 1754026 jKhB\|
0x1B03C1 1770433 <1ffff.
0x1B0861 1771617 RQVVRQP
0x1B0EBD 1773245 uo<-tZ1
0x1B3421 1782817 L$)WQP
0x1B3C5F 1784927 x:^_[]
0x1B4D70 1789296 j@h*d|
0x1B4DB0 1789360 j h3d|
0x1B4EC2 1789634 Affff.
0x1B534F 1790799 A$ffffff.
0x1B5A4F 1792591 z,^_[]
0x1B618C 1794444 j h&f|
0x1B61CC 1794508 j h>f|
0x1B620C 1794572 j hPf|
0x1B74C7 1799367 3D$<3L$8
0x1B9B6B 1809259 Rh1U!SP
0x1B9F7C 1810300 1U!SWSRP
0x1BA0C0 1810624 Sh1U!SP
0x1BB96A 1816938 t$phtg|
0x1BC33F 1819455 t$phtg|
0x1BCDB8 1822136 t$phtg|
0x1BD78F 1824655 t$phtg|
0x1BE104 1827076 t$phtg|
0x1BEB41 1829697 t$phtg|
0x1BF4F2 1832178 t$phtg|
0x1C01FC 1835516 t$Phtg|
0x1C02E2 1835746 \$pj VS
0x1C0B03 1837827 t$Phtg|
0x1C0BE9 1838057 \$pj VS
0x1C10DC 1839324 D$ $xz
0x1C130F 1839887 t$0htg|
0x1C13ED 1840109 \$Pj VS
0x1C14C7 1840327 D$ $xz
0x1C16F8 1840888 t$0htg|
0x1C17D6 1841110 \$Pj VS
0x1C342F 1848367 D$T+|$
0x1C5B42 1858370 fffff.
0x1C5F59 1859417 RRSSPW
0x1C6764 1861476 4Sf;4P
0x1C70E3 1863907 VVSSRP
0x1C82D2 1868498 fffff.
0x1C9111 1872145 4fffff.
0x1CB531 1881393 ffffff.
0x1CCEB2 1887922 fffff.
0x1CD0D2 1888466 Dffff.
0x1CE05D 1892445 QRVWSP
0x1F55C1 2053569 ffffff.
0x1F5E01 2055681 ffffff.
0x1F5EC1 2055873 ffffff.
0x1F6B41 2059073 ffffff.
0x1F7B62 2063202 fffff.
0x1F7FB1 2064305 ffffff.
0x1F8C50 2067536 T$liD$
0x1F900D 2068493 L$`9L$
0x1F909B 2068635 T$\;D$
0x1F90F9 2068729 L$<;\$L
0x1F915F 2068831 |$@9T$<
0x1F919A 2068890 L$L9L$
0x1F91AA 2068906 L$Ls&9
0x1F9238 2069048 L$X;L$H
0x1F9248 2069064 D$H+D$
0x1F9260 2069088 |$X+|$H
0x1F926C 2069100 D$\;|$<
0x1F9410 2069520 |$4!|$
0x1F95D1 2069969 T$$#\$l
0x1F9627 2070055 D$ ;D$
0x1F9639 2070073 T$$9T$
0x1FB713 2078483 u'^_[]
0x1FB7A5 2078629 WVRQPS
0x206FBF 2125759 ](PQRS
0x207561 2127201 F$rZ9^ r%
0x2076A3 2127523 rZ9F r%
0x208E01 2133505 hMbP?h
0x208FF7 2134007 hMbP?h
0x209797 2135959 hMbP?h
0x20B398 2143128 O@;ODsB
0x20E760 2156384 t$,3DN
0x20F092 2158738 fffff.
0x20F616 2160150 T$ 3L$
0x20F85B 2160731 L$HQPR
0x212350 2171728 <ffffff.
0x2136A2 2176674 fffff.
0x213E51 2178641 ffffff.
0x216D62 2190690 fffff.
0x218872 2197618 fffff.
0x21A5E2 2205154 fffff.
0x21E80A 2222090 9>u(Sh
0x21F902 2226434 QQSVWd
0x21FE00 2227712 VC20XC00
0x2223E9 2237417 ARPRQh
0x2235F2 2242034 VSSSSS
0x223B3D 2243389 <ItC<Lt3<Tt#<h
0x223BE6 2243558 A<lt'<tt
0x223DDD 2244061 F +F4+
0x2244E8 2245864 PRRRRR
0x2248B9 2246841 <ItC<Lt3<Tt#<h
0x224962 2247010 A<lt'<tt

Request takedown

Explain why this item should be unpublished from the community. A platform admin will review your request.

Reason
Leaving Threaticon

This link opens an external site that isn't part of the platform.