Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Community Scans bea2ca4c9d9abd1ff214166d...

Community Scan Report

Flagged

bea2ca4c9d9abd1ff214166d638792be974ffad7907a8a8ed0370acba800e815

Detection Ratio

32 / 4097 rules matched

11647 ms scan time
32 rules matched

Matches rule APT17_Sample_FXSST_DLL from malware

Detects Samples related to APT17 activity - file FXSST.DLL

Matched Strings

$s2
Offset (hex) Offset (dec) Length Matched Data
0x707A 28794 5 Sleep
rule APT17_Sample_FXSST_DLL
{Roth
	Date: 2015-05-14
	Identifier: APT17
*/

/* Rule Set ----------------------------------------------------------------- */

rule APT17_Sample_FXSST_DLL {
	meta:
		description = "Detects Samples related to APT17 activity - file FXSST.DLL"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://goo.gl/ZiJyQv"
		date = "2015-05-14"
		hash = "52f1add5ad28dc30f68afda5d41b354533d8bce3"
		id = "e4b9b25e-8895-5ba5-b706-bfb6892c16ae"
	strings:
		$x1 = "Microsoft? Windows? Operating System" fullword wide
		$x2 = "fxsst.dll" fullword ascii

		$y1 = "DllRegisterServer" fullword ascii
		$y2 = ".cSV" fullword ascii

		$s1 = "GetLastActivePopup"
		$s2 = "Sleep"
		$s3 = }

Matches rule APT28_CHOPSTICK from malware

Detects a malware that behaves like CHOPSTICK mentioned in APT28 report

Matched Strings

$s8
Offset (hex) Offset (dec) Length Matched Data
0x7280 29312 12 KERNEL32.dll
rule APT28_CHOPSTICK
{arGen Rule Generator
	Date: 2015-06-02
	Identifier: APT28
*/

/* Rule Set ----------------------------------------------------------------- */

rule APT28_CHOPSTICK {
	meta:
		description = "Detects a malware that behaves like CHOPSTICK mentioned in APT28 report"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://goo.gl/v3ebal"
		date = "2015-06-02"
		hash = "f4db2e0881f83f6a2387ecf446fcb4a4c9f99808"
		score = 60
		id = "08bc4cc2-1844-5218-bb89-20a3ac70a951"
	strings:
		$s0 = "jhuhugit.tmp" fullword ascii /* score: '14.005' */
		$s8 = "KERNEL32.dll" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 14405 times */
		$s9 = "IsDebuggerPresent" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' }

Matches rule APT_Loader_Win32_DShell_3 from malware by FireEye

AuthorFireEye

Matched Strings

$ss1
Offset (hex) Offset (dec) Length Matched Data
0x719F 29087 14 \x00CreateThread\x00
rule APT_Loader_Win32_DShell_3
{You may not use this file except in compliance with the license. The license should have been received with this file. You may obtain a copy of the license at:
// https://github.com/fireeye/red_team_tool_countermeasures/blob/master/LICENSE.txt
rule APT_Loader_Win32_DShell_3
{
    meta:
        date_created = "2020-11-27"
        date_modified = "2020-11-27"
        md5 = "12c3566761495b8353f67298f15b882c"
        rev = 1
        author = "FireEye"
    strings:
        $sb1 = { 6A 40 68 00 30 00 00 [4-32] E8 [4-8] 50 [0-16] E8 [4-150] 6A FF [1-32] 6A 00 6A 00 5? 6A 00 6A 00 [0-}

Matches rule APT_Loader_Win64_PGF_1 from malware by FireEye

base dlls: /lib/payload/techniques/unmanaged_exports/

50×
AuthorFireEye

Matched Strings

$sb1
50×
Offset (hex) Offset (dec) Length Matched Data
0x776 1910 1 \xB9
0x862 2146 1 \xB9
0x14A1 5281 1 \xB9
0x1919 6425 1 \xB9
0x19F1 6641 1 \xB9
0x2ED8 11992 1 \xB9
0x3F2C 16172 1 \xB9
0x3F64 16228 1 \xB9
0x478A 18314 1 \xB9
0x5BD7 23511 1 \xB9
0x6121 24865 1 \xB9
0x70D4 28884 1 \xB9
0x100AB 65707 1 \xB9
0x11A81 72321 1 \xB9
0x11C71 72817 1 \xB9
0x11D59 73049 1 \xB9
0x11E39 73273 1 \xB9
0x12ED7 77527 1 \xB9
0x12F7B 77691 1 \xB9
0x12F7F 77695 1 \xB9
0x130C7 78023 1 \xB9
0x13244 78404 1 \xB9
0x13259 78425 1 \xB9
0x13328 78632 1 \xB9
0x13359 78681 1 \xB9
0x1351E 79134 1 \xB9
0x13540 79168 1 \xB9
0x13598 79256 1 \xB9
0x13727 79655 1 \xB9
0x138C9 80073 1 \xB9
0x139D3 80339 1 \xB9
0x13A43 80451 1 \xB9
0x13A87 80519 1 \xB9
0x13AB2 80562 1 \xB9
0x13AD5 80597 1 \xB9
0x13B1E 80670 1 \xB9
0x13B30 80688 1 \xB9
0x13B86 80774 1 \xB9
0x13BDD 80861 1 \xB9
0x13C3F 80959 1 \xB9
0x13C58 80984 1 \xB9
0x13C82 81026 1 \xB9
0x13E64 81508 1 \xB9
0x13E96 81558 1 \xB9
0x13FE6 81894 1 \xB9
0x13FF1 81905 1 \xB9
0x14073 82035 1 \xB9
0x140AA 82090 1 \xB9
0x1417B 82299 1 \xB9
0x1428C 82572 1 \xB9
rule APT_Loader_Win64_PGF_1
{00 00 FF D0 89 44 24 ?? C7 04 24 08 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? 83 7D ?? 00 75 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 E9 ?? ?? ?? ?? C7 45 ?? 00 00 00 00 C7 45 ?? 00 00 00 00 C7 85 ?? ?? ?? ?? 28 04 00 00 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 85 ?? ?? ?? ?? 02 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? 83 7D ?? 00 74 ?? 8D 85 ?? ?? ?? ?? C7 44 24 ?? 00 00 00 00 8D 95 ?? ?? ?? ?? 83 C2 20 89 14 24 89 C1 E8 ?? ?? ?? ?? 83 EC 08 83 F8 FF 0F 95 C0 84 C0 74 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8B 85 ?? ?? ?? ?? 89 45 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8B 45 ?? 89 04 24 C7 85 ?? ?? ?? ?? 02 00 00 00 E8 ?? ?? ?? ?? 83 EC 08 89 45 ?? EB ?? 8B 45 ?? 89 04 24 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 04 83 7D ?? 00 74 ?? 83 7D ?? 00 75 ?? C7 85 ?? ?? ?? ?? 00 00 00 00 E9 ?? ?? ?? ?? C7 04 24 7E 40 D9 63 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 04 C7 44 24 ?? 8A 40 D9 63 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC 08 89 45 ?? 89 E8 89 45 ?? 8D 85 ?? ?? ?? ?? 89 44 24 ?? 8D 85 ?? ?? ?? ?? 89 04 24 A1 ?? ?? ?? ?? FF D0 83 EC 08 C7 45 ?? 00 00 00 00 8B 55 ?? 8B 85 ?? ?? ?? ?? 39 C2 0F 83 ?? ?? ?? ?? 8B 45 ?? 8B 00 3D FF 0F 00 00 0F 86 ?? ?? ?? ?? 8B 45 ?? 8B 00 39 45 ?? 73 ?? 8B 45 ?? 8B 00 8B 55 ?? 81 C2 00 10 00 00 39 D0 73 ?? C7 45 ?? 01 00 00 00 83 7D ?? 00 0F 84 ?? ?? ?? ?? 8B 45 ?? 8B 00 39 45 ?? 0F 83 ?? ?? ?? ?? 8B 45 ?? 8B 00 8B 4D ?? 8B 55 ?? 01 CA 39 D0 0F 83 ?? ?? ?? ?? B9 00 00 00 00 B8 1C 00 00 00 83 E0 FC 89 C2 B8 00 00 00 00 89 8C 05 ?? ?? ?? ?? 83 C0 04 39 D0 72 ?? 8B 45 ?? 8B 00 C7 44 24 ?? 1C 00 00 00 8D 95 ?? ?? ?? ?? 89 54 24 ?? 89 04 24 A1 ?? ?? ?? ?? C7 85 ?? ?? ?? ?? 02 00 00 00 FF D0 83 EC 0C 8B 85 ?? ?? ?? ?? 83 E0 20 85 C0 74 ?? 8B 45 ?? 8B 00 C7 44 24 ?? 30 14 D4 63 }

Matches rule APT_Loader_Win64_PGF_4 from malware by FireEye

AuthorFireEye

Matched Strings

$e0
Offset (hex) Offset (dec) Length Matched Data
0x4E2CB 320203 3 ,0,
0x3A6B90 3828624 3 ,0,
$e5
Offset (hex) Offset (dec) Length Matched Data
0x1466F6 1337078 3 ,5,
rule APT_Loader_Win64_PGF_4
{-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html"
        author = "FireEye"
        id = "31717164-9876-58f8-af27-d27c81d20fba"
    strings:
        $dlang1 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\utf.d" ascii wide
        $dlang2 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\file.d" ascii wide
        $dlang3 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\format.d" ascii wide
        $dlang4 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\base64.d" ascii wide
        $dlang5 = "C:\\D\\dmd2\\windows\\bin\\..\\..\\src\\phobos\\std\\stdio.d" ascii wide
        $dlang6 = "\\..\\..\\src\\phobos\\std\\utf.d" ascii wide
        $dlang7 = "\\..\\..\\src\\phobos\\std\\file.d" ascii wide
        $dlang8 = "\\..\\..\\src\\phobos\\std\\format.d" ascii wide
        $dlang9 = "\\..\\..\\src\\phobos\\std\\base64.d" ascii wide
        $dlang10 = "\\..\\..\\src\\phobos\\std\\stdio.d" ascii wide
        $dlang11 = "Unexpected '\\n' when converting from type const(char)[] to type int" ascii wide
        $e0 = ",0,"
        $e1 = ",1,"
        $e2 = ",2,"
        $e3 = ",3,"
        $e4 = ",4,"
        $e5 = ",5,"
        $e6 = ",6,"
        $e7 = ",7,"
        $e8 = ",8,"
        $e9 = ",9,"
        $e10 = ",10,"
        $e11 = ",11,"
        $e12 = ",12,"
        $e13 = ",13,"
        $e14 = ",14,"
        $e15 = ",15,"
        $e16 = ",16,"
        $e17 = ",17,"
        $e18 = ",18,"
        $e19 = ",19,"
        $e20 = ",20,"
        $e21 = ",21,"
        $e22 = ",22,"
        $e23 = ",23,"
        $e24 = ",24,"
        $e25 = ",25,"
        $e26 = ",26,"
        $e27 = ",27,"
        $e28 = ",28,"
 }

Matches rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3 from malware by Mandiant

Detects VEILEDSIGNAL malware

AuthorMandiant

Matched Strings

$si3
Offset (hex) Offset (dec) Length Matched Data
0x71A0 29088 12 CreateThread
rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3
{BinaryToStringA" fullword
      $si2 = "BCryptGenerateSymmetricKey" fullword
      $si3 = "CreateThread" fullword
      $ss1 = "ChainingModeGCM" wide
      $ss2 = "__tutma" fullword
   condition:
      (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them
}

rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_3 {
   meta:
      description = "Detects VEILEDSIGNAL malware"
      author = "Mandiant"
      score = 75
      disclaimer = "This rule is meant for hunting and is not tested to run in a production environment"
      md5 = "c6441c961dcad0fe127514a918eaabd4"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "82790c65-1d93-509b-95df-841543943c30"
   strings:
      $ss1 = { 61 70 70 6C 69 63 61 74 69 6F 6E 2F 6A 73 6F 6E 2C 20 74 65 78 74 2F 6A 61 76 61 73 63 72 69 70 74 2C 20 2A 2F 2A 3B 20 71 3D 30 2E 30 31 00 00 61 63 63 65 70 74 00 00 65 6E 2D 55 53 2C 65 6E 3B 71 3D 30 2E 39 00 00 61 63 63 65 70 74 2D 6C 61 6E 67 75 61 67 65 00 63 6F 6F 6B 69 65 00 00 }
      $si1 = "HttpSendRequestW" fullword
      $si2 = "CreateNamedPipeW" fullword
      $si3 = "CreateThread" fullword
      $se1 = "DllGetClassObject" fullword
   condition:
      (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them
}

rule APT_NK_MAL_M_Hunting_VEILEDSIGNAL_4 {
   meta:
      description = "Detects VEILEDSIGNAL malware"
      author = "Mandiant"
      score = 75
      disclaimer = "This rule is meant for hunting and is not tested to run in a production environment"
      hash1 = "404b09def6054a281b41d309d809a428" 
      hash2 = "c6441c961dcad0fe127514a918eaabd4"
      reference = "https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise"
      date = "2023-04-20"
      id = "379e6471-3c4f-5c72-b8fd-17f481e89ac6"
   strings:
      $sb1 = { FF 15 FC 76 01 00 8B F0 85 C0 74 ?? 8D }

Matches rule Dridex_Trojan_XML from malware by Florian Roth (Nextron Systems) @4nc4p

Dridex Malware in XML Document

AuthorFlorian Roth (Nextron Systems) @4nc4p

Matched Strings

$c_xml
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 14 <?xml version=
rule Dridex_Trojan_XML
{
	meta:
		description = "Dridex Malware in XML Document"
		author = "Florian Roth (Nextron Systems) @4nc4p"
		reference = "https://threatpost.com/dridex-banking-trojan-spreading-via-macros-in-xml-files/111503"
		date = "2015/03/08"
		hash1 = "88d98e18ed996986d26ce4149ae9b2faee0bc082"
		hash2 = "3b2d59adadf5ff10829bb5c27961b22611676395"
		hash3 = "e528671b1b32b3fa2134a088bfab1ba46b468514"
		hash4 = "981369cd53c022b434ee6d380aa9884459b63350"
		hash5 = "96e1e7383457293a9b8f2c75270b58da0e630bea"
		id = "a8f3406c-f8b0-559f-be12-6b2a7d401ac2"
	strings:
		// can be ascii or wide formatted - therefore no restriction
		$c_xml      = "<?xml version="
		$c_word     = "<?mso-application progid=\"Word.Document\"?>"
		$c_macro    = "w:macrosPresent=\"yes\""
		$c_binary   }

Matches rule Exploit_MS15_077_078 from exploit

MS15-078 / MS15-077 exploit - generic signature

Matched Strings

$s6
Offset (hex) Offset (dec) Length Matched Data
0x76F6 30454 12 DeleteObject
rule Exploit_MS15_077_078
{n Roth
	Date: 2015-07-21
	Identifier: MS15-077 MS15-078
*/

/* Rule Set ----------------------------------------------------------------- */

rule Exploit_MS15_077_078 {
	meta:
		description = "MS15-078 / MS15-077 exploit - generic signature"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "https://code.google.com/p/google-security-research/issues/detail?id=473&can=1&start=200"
		date = "2015-07-21"
		hash1 = "18e3e840a5e5b75747d6b961fca66a670e3faef252aaa416a88488967b47ac1c"
		hash2 = "0b5dc030e73074b18b1959d1cf7177ff510dbc2a0ec2b8bb927936f59eb3d14d"
		hash3 = "fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9"
		hash4 = "ad6bb982a1ecfe080baf0a2b27950f989c107949b1cf02b6e0907f1a568ece15"
		id = "57f6db11-9d93-53fd-ab68-c6c3eadae2da"
	strings:
		$s1 = "GDI32.DLL" fullword ascii
		$s2 = "atmfd.dll" fullword wide
		$s3 = "AddFontMemResourceEx" fullword ascii
		$s4 = "NamedEscape" fullword ascii
		$s5 = "CreateBitmap" fullword ascii
		$s6 = "DeleteObject" fu}

Matches rule FSO_s_indexer from malware

Webshells Auto-generated - file indexer.asp

50×

Matched Strings

$s3
50×
Offset (hex) Offset (dec) Length Matched Data
0x1F4 500 1
0xCF5 3317 1
0x16CD 5837 1
0x17A1 6049 1
0x17AA 6058 1
0x1951 6481 1
0x1E1D 7709 1
0x1F76 8054 1
0x1F9B 8091 1
0x20A0 8352 1
0x20EE 8430 1
0x2269 8809 1
0x2272 8818 1
0x235E 9054 1
0x25C2 9666 1
0x25C7 9671 1
0x271C 10012 1
0x27FB 10235 1
0x28B4 10420 1
0x28BC 10428 1
0x2912 10514 1
0x2964 10596 1
0x2C63 11363 1
0x2C76 11382 1
0x2CF1 11505 1
0x3133 12595 1
0x32F6 13046 1
0x3641 13889 1
0x3650 13904 1
0x39ED 14829 1
0x3A16 14870 1
0x3A2B 14891 1
0x40CB 16587 1
0x40D9 16601 1
0x4209 16905 1
0x4297 17047 1
0x4300 17152 1
0x4314 17172 1
0x46BA 18106 1
0x48A7 18599 1
0x49F7 18935 1
0x4C9B 19611 1
0x4CAB 19627 1
0x5117 20759 1
0x54F3 21747 1
0x55ED 21997 1
0x59CD 22989 1
0x5A47 23111 1
0x5A96 23190 1
0x5B11 23313 1
rule FSO_s_indexer
{ithub Archive - file matamu.php"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		hash = "d477aae6bd2f288b578dbf05c1c46b3aaa474733"
		id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
	strings:
		$s2 = "$command .= ' -F';" fullword
		$s3 = "/* We try and match a cd command. */" fullword
		}

Matches rule MAL_Sharpshooter_Excel4 from malware by John Lambert, Florian Roth

Detects Excel documents weaponized with Sharpshooter

AuthorJohn Lambert, Florian Roth

Matched Strings

$f1
Offset (hex) Offset (dec) Length Matched Data
0x71A0 29088 12 CreateThread
rule MAL_Sharpshooter_Excel4
{
   meta:
      description = "Detects Excel documents weaponized with Sharpshooter"
      author = "John Lambert, Florian Roth"
      reference = "https://github.com/mdsecactivebreach/SharpShooter"
      reference2="https://outflank.nl/blog/2018/10/06/old-school-evil-excel-4-0-macros-xlm/"
      reference3 = "https://gist.github.com/JohnLaTwC/efab89650d6fcbb37a4221e4c282614c"
      reference4 = "https://docs.microsoft.com/en-us/openspecs/office_file_formats/ms-xls/00b5dd7d-51ca-4938-b7b7-483fe0e5933b"
      date = "2020-03-27"
      score = 70
      hash="ccef64586d25ffcb2b28affc1f64319b936175c4911e7841a0e28ee6d6d4a02d"
      id = "a79e3afe-e8f9-5e56-a131-bb1b346df471"
   strings:
      $header_docf = { D0 CF 11 E0 }
      $s1 = "Excel 4.0 Macros"
      $f1 = "CreateThread" ascii fullword
      $f2 }

Matches rule M_Hunting_Python_Backdoor_CommandParser_1 from malware by Mandiant

Finds strings indicative of the vmsyslog.py python backdoor.

AuthorMandiant

Matched Strings

$key3
Offset (hex) Offset (dec) Length Matched Data
0x7A7F 31359 8 download
rule M_Hunting_Python_Backdoor_CommandParser_1
{_Hunting_Python_Backdoor_CommandParser_1 {
   meta:
      author = "Mandiant"
      md5 = "61ab3f6401d60ec36cd3ac980a8deb75"
      description = "Finds strings indicative of the vmsyslog.py python backdoor."
      id = "15cbca01-24e6-5538-bcfd-c3222337aaf5"
   strings:
      $key1 = "self.conn.readInt8()" ascii
      $key2 = "upload" ascii
      $key3 = "download" ascii
      $key4 = "shell" ascii
      $key5 = "execute" ascii
      $re1 = /def\srun.{0,20}command\s?=\s?self\.conn\.readInt8\(\).{,75}upload.{,75}download.{,75}shell.{,75}execute/s
   conditio}

Matches rule Malware_MsUpdater_String_in_EXE from malware by Florian Roth

MSUpdater String in Executable

AuthorFlorian Roth

Matched Strings

$s3
Offset (hex) Offset (dec) Length Matched Data
0x786A 30826 21 LookupPrivilegeValueA
rule Malware_MsUpdater_String_in_EXE
{2d444865fa8320337467313e4026b9f78"
		id = "5c8e0629-b5f2-5933-8c74-c49b756aaf18"
	strings:
		$x0 = "WUAUCLT.EXE" fullword wide /* PEStudio Blacklist: strings */ /* score: '20.01' */
		$x1 = "%s\\tmp%d.exe" fullword ascii /* score: '14.01' */
		$x2 = "Microsoft Corporation. All rights reserved." fullword wide /* score: '8.04' */

		$s1 = "Microsoft Windows Operating System" fullword wide /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 4 times */
		$s2 = "InternetQueryOptionA" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 166 times */
		$s3 = "LookupPrivilegeValueA" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 336 times */
		$s4 = "WNetEnumResourceA" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 29 times */
		$s5 = "HttpSendRequestExA" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 87 times */
		$s6 = "PSAPI.DLL" fullword ascii /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 420 times */
		$s7 = "Microsoft(R) Windows(R) Operating System" fullword wide /* PEStudio Blacklist: strings */ /* score: '5' */ /* Goodware String - occured 128 }

Matches rule PUA_VULN_Renamed_Driver_Avastsoftware_Aswarpotsys_Avastantivirus_EBE2

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x125C1 75201 19 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00

Matches rule PUA_VULN_Renamed_Driver_Cpuid_Cpuzsys_Cpuidservice_0D37 from malware by Florian Roth

Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - cpuz.sys

AuthorFlorian Roth

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x125C1 75201 29 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
rule PUA_VULN_Renamed_Driver_Cpuid_Cpuzsys_Cpuidservice_0D37
{730068002000440072006900760065007200200066006f0072002000570069006e0064006f007700730020004e0054 } /* FileDescription SWinFlashDriverforWindowsNT */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]00500068006f0065006e0069007800200054006500630068006e006f006c006f0067006900650073002c0020004c00740064002e } /* CompanyName PhoenixTechnologiesLtd */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0031002e0036002e0031002e0030 } /* FileVersion  */
		$ = { 00500072006f006400750063007400560065007200730069006f006e[1-8]0031002e0036002e0031002e0030 } /* ProductVersion  */
		$ = { 0049006e007400650072006e0061006c004e0061006d0065[1-8]00500048004c004100530048004e0054 } /* InternalName PHLASHNT */
		$ = { 00500072006f0064007500630074004e0061006d0065[1-8]00570069006e00500068006c006100730068 } /* ProductName WinPhlash */
		$ = { 004f0072006900670069006e0061006c00460069006c0065006e0061006d0065[1-8]00500048004c004100530048004e0054002e005300590053 } /* OriginalFilename PHLASHNTSYS */
		$ = { 004c006500670061006c0043006f0070007900720069006700680074[1-8]002800630029002000500068006f0065006e0069007800200054006500630068006e006f006c006f0067006900650073002c0020004c00740064002e00200032003000300030002d0032003000300033 } /* LegalCopyright cPhoenixTechnologiesLtd */
	condition:
		uint16(0) == 0x5a4d and filesize < 100KB and all of them and not filename matches /PhlashNT/i
}


rule PUA_VULN_Renamed_Driver_Arthurliberman_Alsysiosys_Alsysio_7196 {
	meta:
		description = "Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - ALSysIO64.sys"
		author = "Florian Roth"
		reference = "https://github.com/magicsword-io/LOLDrivers"
		hash = "7196187fb1ef8d108b380d37b2af8efdeb3ca1f6eefd37b5dc114c609147216d"
		date = "2024-08-07"
		score = 70
		id = "a197bb49-05c6-5f73-a598-2df9ff503ffa"
	strings:
		$ = { 00460069006c0065004400650073006300720069007000740069006f006e[1-8]0041004c0053007900730049004f } /* FileDescription ALSysIO */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]0041007200740068007500720020004c0069006200650072006d0061006e } /* CompanyName ArthurLiberman */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0032002e0030002e0038002e0030 } /* FileVersion  */
		$ = { 00500072006f006400750063007400560065007200730069006f006e[1-8]0032002e0030002e0038002e0030 } /* ProductVersion  */
		$ = { 0049006e007400650072006e0061006c004e0061006d0065[1-8]0041004c0053007900730049004f002e007300790073 } /* InternalName ALSysIOsys */
		$ = { 00500072006f0064007500630074004e0061006d0065[1-8]0041004c0053007900730049004f } /* ProductName ALSysIO */
		$ = { 004f0072006900670069006e0061006c00460069006c0065006e0061006d0065[1-8]0041004c0053007900730049004f002e007300790073 } /* OriginalFilename ALSysIOsys */
		$ = { 004c006500670061006c0043006f0070007900720069006700680074[1-8]0043006f0070007900720069006700680074002000280043002900200032003000300033002d003200300030003900200041007200740068007500720020004c0069006200650072006d0061006e } /* LegalCopyright CopyrightCArthurLiberman */
	condition:
		uint16(0) == 0x5a4d and filesize < 100KB and all of them and not filename matches /ALSysIO64/i
}


rule PUA_VULN_Renamed_Driver_Advancedmicrodevices_Aoddriversys_Amdoverdriveservicedriver_F4DC {
	meta:
		description = "Detects renamed vulnerable driver mentioned in LOLDrivers project using VersionInfo values from the PE header - AODDriver.sys"
		author = "Florian Roth"
		reference = "https://github.com/magicsword-io/LOLDrivers"
		hash = "f4dc11b7922bf2674ca9673638e7fe4e26aceb0ebdc528e6d10c8676e555d7b2"
		hash = "070ff602cccaaef9e2b094e03983fd7f1bf0c0326612eb76593eabbf1bda9103"
		date = "2024-08-07"
		score = 70
		id = "44890447-4682-561a-9009-adc3e3b9ac57"
	strings:
		$ = { 00460069006c0065004400650073006300720069007000740069006f006e[1-8]0041004d00440020004f00760065007200440072006900760065002000530065007200760069006300650020004400720069007600650072 } /* FileDescription AMDOverDriveServiceDriver */
		$ = { 0043006f006d00700061006e0079004e0061006d0065[1-8]0041006400760061006e0063006500640020004d006900630072006f00200044006500760069006300650073 } /* CompanyName AdvancedMicroDevices */
		$ = { 00460069006c006500560065007200730069006f006e[1-8]0034002e0032002e00300020006200750069006c0074002000620079003a002000570069006e00440044004b } /* Fi}

Matches rule PUA_VULN_Renamed_Driver_Intelcorporation_Iqvwsys_Intelriqvwsys_1F81

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x125C1 75201 41 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00

Matches rule PUA_VULN_Renamed_Driver_Radiantsystemsinc_Radhwmgrsys_Radiantsystemsinchardwaremanagerdriver_0F30

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x125C1 75201 23 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00

Matches rule PUA_VULN_Renamed_Driver_Realteksemiconductorcorp_Rtportsys_Realtekportio_FF32

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x125C1 75201 44 \x00L\x00e\x00g\x00a\x00l\x00C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00\x00\x00C\x00o\x00p\x00y\x00r\x00i\x00g

Matches rule PUA_VULN_Renamed_Driver_Sysinternalswwwsysinternalscom_Procexpsys_7795

Matched Strings

$
Offset (hex) Offset (dec) Length Matched Data
0x12759 75609 11 \x00P\x00r\x00o\x00d\x00u\x00

Matches rule SUSP_EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22_1 from exploit by Florian Roth

Detects payload as seen in PoC code to exploit Workspace ONE Access freemarker server-side template injection CVE-2022-22954

AuthorFlorian Roth

Matched Strings

$fpg4
Offset (hex) Offset (dec) Length Matched Data
0x125CC 75212 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
0x125E0 75232 18 C\x00o\x00p\x00y\x00r\x00i\x00g\x00h\x00t\x00
$fpg6
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 5 <?xml
rule SUSP_EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22_1
{
   meta:
      old_rule_name = "EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22"
      description = "Detects payload as seen in PoC code to exploit Workspace ONE Access freemarker server-side template injection CVE-2022-22954"
      author = "Florian Roth"
      reference = "https://github.com/sherlocksecurity/VMware-CVE-2022-22954"
      reference2 = "https://twitter.com/rwincey/status/1512241638994853891/photo/1"
      date = "2022-04-08"
      modified = "2025-03-29"
      score = 60
      id = "3ff617bb-6dcd-576f-a1c3-7be1c19c0d5a"
   strings:
      $x2 = "${\"freemarker.template.utility.Execute\"?new()("
      $x3 = "cat /etc/passwd\")).(#execute=#instancemanager.newInstance(\"freemarker.template.utility.Execute"
      $x4 = "cat /etc/passwd\\\")).(#execute=#instancemanager.newInstance(\\\"freemarker.template.utility.Execute"
      $x5 = "cat /etc/shadow\")).(#execute=#instancemanager.newInstance(\"freemarker.template.utility.Execute"
      $x6 = "cat /etc/shadow\\\")).(#execute=#instancemanager.newInstance(\\\"freemarker.template.utility.Execute"

      $fpg1 = "All Rights"
      $fpg2 = "<html"
      $fpg3 = "<HTML"
      $fpg4 = "Copyright" ascii wide
      $fpg5 = "License"
      $fpg6 = "<?xml"
      $fpg7 = "Help" fullword
      $fpg8 = "COPYRIGHT" ascii wide fullword
      $fpg}

Matches rule SUSP_Known_Type_Cloaked_as_JPG from malware by Florian Roth (Nextron Systems)

Detects a non-JPEG file type cloaked as .jpg

51×
AuthorFlorian Roth (Nextron Systems)

Matched Strings

$mz
50×
Offset (hex) Offset (dec) Length Matched Data
0x0 0 2 MZ
0x1444B 83019 2 MZ
0x1EA8F 125583 2 MZ
0x3785C 227420 2 MZ
0x404D2 263378 2 MZ
0x4865B 296539 2 MZ
0x5B112 373010 2 MZ
0x5C5B5 378293 2 MZ
0x5C712 378642 2 MZ
0x84F23 544547 2 MZ
0x85A34 547380 2 MZ
0x9AB67 633703 2 MZ
0xAE1FE 713214 2 MZ
0xBFFDE 786398 2 MZ
0xCC94B 837963 2 MZ
0xD0E70 855664 2 MZ
0xD5C0B 875531 2 MZ
0xDA777 894839 2 MZ
0xDE849 911433 2 MZ
0xDF615 914965 2 MZ
0xE2770 927600 2 MZ
0x117F8E 1146766 2 MZ
0x134A89 1264265 2 MZ
0x13789C 1276060 2 MZ
0x138F3E 1281854 2 MZ
0x144FF7 1331191 2 MZ
0x147589 1340809 2 MZ
0x159516 1414422 2 MZ
0x161F42 1449794 2 MZ
0x16DE10 1498640 2 MZ
0x183FB8 1589176 2 MZ
0x1AC4DC 1754332 2 MZ
0x1AEFEF 1765359 2 MZ
0x1B4C46 1788998 2 MZ
0x1C753D 1865021 2 MZ
0x1C7A31 1866289 2 MZ
0x1CA8B2 1878194 2 MZ
0x1D8E01 1936897 2 MZ
0x1E5528 1987880 2 MZ
0x206F80 2125696 2 MZ
0x21B80E 2209806 2 MZ
0x234A6D 2312813 2 MZ
0x239C2D 2333741 2 MZ
0x23BBE5 2341861 2 MZ
0x23F75F 2357087 2 MZ
0x244F73 2379635 2 MZ
0x247507 2389255 2 MZ
0x254D89 2444681 2 MZ
0x25985A 2463834 2 MZ
0x275A4A 2579018 2 MZ
$a1
Offset (hex) Offset (dec) Length Matched Data
0x4E 78 38 This program cannot be run in DOS mode
rule SUSP_Known_Type_Cloaked_as_JPG
{gmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md)

*/

/* Performance killer - value isn't big enough
rule Embedded_EXE_Cloaking {
        meta:
                description = "Detects an embedded executable in a non-executable file"
                license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
                date = "2015/02/27"
                score = 65
        strings:
                $noex_png = { 89 50 4E 47 }
                $noex_pdf = { 25 50 44 46 }
                $noex_rtf = { 7B 5C 72 74 66 31 }
                $noex_jpg = { FF D8 FF E0 }
                $noex_gif = { 47 49 46 38 }
                $mz  = { 4D 5A }
                $a1 = "This program cannot be run in DOS mode"
                $a2 = "This progr}

Matches rule SUSP_PS1_JAB_Pattern_Jun22_1 from malware by Florian Roth (Nextron Systems)

Detects suspicious UTF16 and Base64 encoded PowerShell code that starts with a $ sign and a single char variable

47×
AuthorFlorian Roth (Nextron Systems)

Matched Strings

$xc1
47×
Offset (hex) Offset (dec) Length Matched Data
0x3B43B 242747 2 JA
0x5555F 349535 2 JA
0x64C98 412824 2 JA
0x7969F 497311 2 JA
0x99FAC 630700 2 JA
0xB70F2 749810 2 JA
0xEDF46 974662 2 JA
0xF2A40 993856 2 JA
0xFD2D4 1037012 2 JA
0x11B498 1160344 2 JA
0x14EF24 1371940 2 JA
0x15AAA5 1419941 2 JA
0x1877E4 1603556 2 JA
0x1A2567 1713511 2 JA
0x1A7905 1734917 2 JA
0x1D3067 1912935 2 JA
0x1D5A6F 1923695 2 JA
0x1F9422 2069538 2 JA
0x1FFE34 2096692 2 JA
0x236A10 2320912 2 JA
0x237CF1 2325745 2 JA
0x238BEF 2329583 2 JA
0x260E21 2493985 2 JA
0x269145 2527557 2 JA
0x2702EE 2556654 2 JA
0x273B95 2571157 2 JA
0x29E00B 2744331 2 JA
0x2A1A42 2759234 2 JA
0x2A8906 2787590 2 JA
0x2BB6E5 2864869 2 JA
0x2EC2BC 3064508 2 JA
0x2F358F 3093903 2 JA
0x2F4535 3097909 2 JA
0x2F9994 3119508 2 JA
0x2FAF9B 3125147 2 JA
0x2FC776 3131254 2 JA
0x3034BB 3159227 2 JA
0x349E5B 3448411 2 JA
0x380C35 3673141 2 JA
0x3A05A0 3802528 2 JA
0x3A14D5 3806421 2 JA
0x3A5326 3822374 2 JA
0x3ADE10 3857936 2 JA
0x3B0E8A 3870346 2 JA
0x3B509C 3887260 2 JA
0x3EA404 4105220 2 JA
0x3F423C 4145724 2 JA
rule SUSP_PS1_JAB_Pattern_Jun22_1
{
   meta:
      description = "Detects suspicious UTF16 and Base64 encoded PowerShell code that starts with a $ sign and a single char variable"
      author = "Florian Roth (Nextron Systems)"
      reference = "Internal Research"
      date = "2022-06-10"
      score= 70
      id = "9ecca7d9-3b63-5615-a223-5efa1c53510e"
   strings:
      /* 
         with spaces : $c = $ 
         https://gchq.github.io/CyberChef/#recipe=Fork('%5C%5Cn','%5C%5Cn',false)Encode_text('UTF-16LE%20(1200)')To_Base64('A-Za-z0-9%2B/%3D')Encode_text('UTF-16LE%20(1200)'/disabled)To_Hex('Space',0)&input=JHAgPSAkRW52OnRlbQokeCA9ICRteXZhcjsKJHggPSBJbnZva2Ut
      */
      /* ASCII */ 
      $xc1 = { 4a 41 4}

Matches rule StuxNet_Malware_1 from malware by Florian Roth

Stuxnet Sample - file malware.exe

50×
AuthorFlorian Roth

Matched Strings

$op3
50×
Offset (hex) Offset (dec) Length Matched Data
0x7AE8 31464 2 tp
0x4BDD0 310736 2 tp
0x50BD8 330712 2 tp
0x537CC 341964 2 tp
0x53E9A 343706 2 tp
0xA2B25 666405 2 tp
0xA3A24 670244 2 tp
0xA7BAF 687023 2 tp
0xBB40C 766988 2 tp
0xBFE3A 785978 2 tp
0xD1929 858409 2 tp
0xE7378 947064 2 tp
0xEFDDE 982494 2 tp
0xFED96 1043862 2 tp
0x10CD74 1101172 2 tp
0x10EE1F 1109535 2 tp
0x110441 1115201 2 tp
0x1144D4 1131732 2 tp
0x118F1B 1150747 2 tp
0x1223B3 1188787 2 tp
0x13FB73 1309555 2 tp
0x141716 1316630 2 tp
0x14376F 1324911 2 tp
0x177E93 1539731 2 tp
0x17D2E6 1561318 2 tp
0x18E10D 1630477 2 tp
0x192069 1646697 2 tp
0x196CF7 1666295 2 tp
0x1A0732 1705778 2 tp
0x1A1B7E 1710974 2 tp
0x1B3728 1783592 2 tp
0x1B684B 1796171 2 tp
0x1EA3D4 2008020 2 tp
0x1EB91D 2013469 2 tp
0x214AF7 2181879 2 tp
0x23056A 2295146 2 tp
0x233E6A 2309738 2 tp
0x26A1E8 2531816 2 tp
0x2904D5 2688213 2 tp
0x292C53 2698323 2 tp
0x2A2D99 2764185 2 tp
0x2A3E68 2768488 2 tp
0x2A5DE9 2776553 2 tp
0x2B14F6 2823414 2 tp
0x2B7557 2848087 2 tp
0x2CC8E0 2935008 2 tp
0x2E2306 3023622 2 tp
0x2FF056 3141718 2 tp
0x2FF7FF 3143679 2 tp
0x30F341 3208001 2 tp
rule StuxNet_Malware_1
{rian Roth
	Date: 2016-07-09
	Identifier: Stuxnet
*/

/* Rule Set ----------------------------------------------------------------- */

rule StuxNet_Malware_1 {
	meta:
		description = "Stuxnet Sample - file malware.exe"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "Internal Research"
		date = "2016-07-09"
		hash1 = "9c891edb5da763398969b6aaa86a5d46971bd28a455b20c2067cb512c9f9a0f8"
		id = "1f475dc3-ebb3-508f-b696-3d9ea270b13d"
	strings:
		 // 0x10001778 8b 45 08  mov     eax, dword ptr [ebp + 8]
		 // 0x1000177b 35 dd 79 19 ae    xor     eax, 0xae1979dd
		 // 0x10001780 33 c9     xor     ecx, ecx
		 // 0x10001782 8b 55 08  mov     edx, dword ptr [ebp + 8]
		 // 0x10001785 89 02     mov     dword ptr [edx], eax
		 // 0x10001787 89 ?? ??  mov     dword ptr [edx + 4], ecx
		 $op1 = { 8b 45 08 35 dd 79 19 ae 33 c9 8b 55 08 89 02 89 }
		 // 0x10002045 74 36     je      0x1000207d
		 // 0x10002047 8b 7f 08  mov     edi, dword ptr [edi + 8]
		 // 0x1000204a 83 ff 00  cmp     edi, 0
		 // 0x1000204d 74 2e     je      0x1000207d
		 // 0x1000204f 0f b7 1f  movzx   ebx, word ptr [edi]
		 // 0x10002052 8b 7f 04  mov     edi, dword ptr [edi + 4]
		 $op2 = { 74 36 8b 7f 08 83 ff 00 74 2e 0f b7 1f 8b 7f 04 }
		 // 0x100020cf 74 70     je      0x10002141
		 // 0x100020d1 81 78 05 8d 54 24 04      cmp     dword ptr [eax + 5], 0x424548d
		 // 0x100020d8 75 1b     jne     0x100020f5
		 // 0x100020da 81 78 08 04 cd ?? ??      cmp     dword ptr [eax + 8], 0xc22ecd04
		 $op3 = { 74 70}

Matches rule Susp_Indicators_EXE from malware

Detects packed NullSoft Inst EXE with characteristics of NetWire RAT

Matched Strings

$s1
Offset (hex) Offset (dec) Length Matched Data
0x69A0 27040 41 Software\Microsoft\Windows\CurrentVersion
rule Susp_Indicators_EXE
{lorian Roth
   Date: 2018-01-05
   Identifier: NetWire
   Reference: https://pastebin.com/8qaiyPxs
*/

/* Rule Set ----------------------------------------------------------------- */

rule Susp_Indicators_EXE {
   meta:
      description = "Detects packed NullSoft Inst EXE with characteristics of NetWire RAT"
      license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://pastebin.com/8qaiyPxs"
      date = "2018-01-05"
      score = 60
      hash1 = "6de7f0276afa633044c375c5c630740af51e29b6a6f17a64fbdd227c641727a4"
      id = "b4015c24-d18e-51eb-9854-8cc0e6dba4d0"
   strings:
      $s1 = "Software\\Microsoft\\Windows\\CurrentVersion"
      $s2 = "Error! Bad token or i}

Matches rule TrojanDownloader from malware

Trojan Downloader - Flash Exploit Feb15

Matched Strings

$s6
Offset (hex) Offset (dec) Length Matched Data
0x7126 28966 15 GetCommandLineA
$s7
Offset (hex) Offset (dec) Length Matched Data
0x70D6 28886 11 ExitProcess
$s8
Offset (hex) Offset (dec) Length Matched Data
0x71FA 29178 11 CreateFileA
$s10
Offset (hex) Offset (dec) Length Matched Data
0x70B6 28854 17 GetCurrentProcess
$s21
Offset (hex) Offset (dec) Length Matched Data
0x7228 29224 9 WriteFile
$s24
Offset (hex) Offset (dec) Length Matched Data
0x7270 29296 14 GetProcAddress
rule TrojanDownloader
{-------------------------------------------------- */

rule TrojanDownloader {
	meta:
		description = "Trojan Downloader - Flash Exploit Feb15"
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		reference = "http://goo.gl/wJ8V1I"
		date = "2015/02/11"
		hash = "5b8d4280ff6fc9c8e1b9593cbaeb04a29e64a81e"
		score = 60
		id = "d61f59ef-31a3-5e52-9525-61910bb150db"
	strings:
		$x1 = "Hello World!" fullword ascii
		$x2 = "CONIN$" fullword ascii

		$s6 = "GetCommandLineA" fullword ascii
		$s7 = "ExitProcess" fullword ascii
		$s8 = "CreateFileA" fullword ascii

		$s5 = "SetConsoleMode" fullword ascii
		$s9 = "TerminateProcess" fullword ascii
		$s10 = "GetCurrentProcess" fullword ascii
		$s11 = "UnhandledExceptionFilter" fullword ascii
		$s3 = "user32.dll" fullword ascii
		$s16 = "GetEnvironmentStrings" fullword ascii
		$s2 = "GetLastActivePopup" fullword ascii
		$s17 = "GetFileType" fullword ascii
		$s19 = "HeapCreate" fullword ascii
		$s20 = "VirtualFree" fullword ascii
		$s21 = "WriteFile" fullword ascii
		$s22 = "GetOEMCP" fullword ascii
		$s23 = "VirtualAlloc" fullword ascii
		$s24 = "GetProcAddress" fullword ascii
		$s26 = "FlushFileBuffers" fullword asci}

Matches rule UBoatRAT from malware

Detects UBoat RAT Samples

51×

Matched Strings

$op1
Offset (hex) Offset (dec) Length Matched Data
0x40 64 64 \x0E\x1F\xBA\x0E\x00\xB4\x09\xCD!\xB8\x01L\xCD!This program cannot be run in DOS mode.\x0D\x0D\x0A$\x00\x00\x00\x00\x00\x00\x00
$vprotect
50×
Offset (hex) Offset (dec) Length Matched Data
0x1284D 75853 2 .v
0x12A1D 76317 2 .v
0x12AF3 76531 2 .v
0x33B5B 211803 2 .v
0x37700 227072 2 .v
0x42A3A 272954 2 .v
0x5B49B 373915 2 .v
0x5C54D 378189 2 .v
0x5EC70 388208 2 .v
0x654FA 414970 2 .v
0x6AD6B 437611 2 .v
0x7EC20 519200 2 .v
0x9CF8D 642957 2 .v
0xAF35A 717658 2 .v
0xB02E5 721637 2 .v
0xB8C8B 756875 2 .v
0xCA29C 828060 2 .v
0xCA3C6 828358 2 .v
0xCB33C 832316 2 .v
0xD4455 869461 2 .v
0xD579B 874395 2 .v
0x10D62E 1103406 2 .v
0x142A23 1321507 2 .v
0x1465BE 1336766 2 .v
0x154F75 1396597 2 .v
0x157A78 1407608 2 .v
0x165850 1464400 2 .v
0x1769D3 1534419 2 .v
0x17DA85 1563269 2 .v
0x18AE1B 1617435 2 .v
0x191B4E 1645390 2 .v
0x19477E 1656702 2 .v
0x1B5635 1791541 2 .v
0x1BC93D 1820989 2 .v
0x1BD12B 1823019 2 .v
0x1D5268 1921640 2 .v
0x1FA49E 2073758 2 .v
0x200A9D 2099869 2 .v
0x2064F8 2123000 2 .v
0x20AC0F 2141199 2 .v
0x20F099 2158745 2 .v
0x24A343 2401091 2 .v
0x25D052 2478162 2 .v
0x271194 2560404 2 .v
0x286028 2646056 2 .v
0x29DD97 2743703 2 .v
0x2B5B8F 2841487 2 .v
0x2B84A4 2852004 2 .v
0x2BBA75 2865781 2 .v
0x2D830A 2982666 2 .v
rule UBoatRAT
{t
   Author: Florian Roth
   Date: 2017-11-28
   Identifier: UBoatRAT
   Reference: https://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/
*/

rule UBoatRAT {
   meta:
      description = "Detects UBoat RAT Samples"
      license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/"
      date = "2017-11-29"
      hash1 = "04873dbd63279228a0a4bb1184933b64adb880e874bd3d14078161d06e232c9b"
      hash2 = "7b32f401e2ad577e8398b2975ecb5c5ce68c5b07717b1e0d762f90a6fbd8add1"
      hash3 = "42d8a84cd49ff3afacf3d549fbab1fa80d5eda0c8625938b6d32e18004b0edac"
      hash4 = "6bea49e4260f083ed6b73e100550ecd22300806071f4a6326e0544272a84526c"
      hash5 = "cf832f32b8d27cf9911031910621c21bd3c20e71cc062716923304dacf4dadb7"
      hash6 = "bf7c6e911f14a1f8679c9b0c2b183d74d5accd559e17297adcd173d76755e271"
      id = "f7f745c2-648d-5937-8d06-f5d1b6ed7e11"
   strings:
      $s1 = "URLDownloadToFileA" ascii
      $s2 = "GetModuleFileNameW" ascii
      $s4 = "WININET.dll" ascii
      $s5 = "urlmon.dll" ascii
      $s6 = "WTSAPI32.dll" ascii
      $s7 = "IPHLPAPI.DLL" ascii

      $op1 = { 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68
               69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F
               74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20
               6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 }

      $vprotect = { 2E 76}

Matches rule VUL_Exchange_CVE_2020_0688 from exploit by Florian Roth (Nextron Systems)

Detects static validation key used by Exchange server in web.config

AuthorFlorian Roth (Nextron Systems)

Matched Strings

$h1
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 6 <?xml
rule VUL_Exchange_CVE_2020_0688
{
   meta:
      description = "Detects static validation key used by Exchange server in web.config"
      author = "Florian Roth (Nextron Systems)"
      reference = "https://www.thezdi.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys"
      date = "2020-02-26"
      score = 60
      id = "1065f297-0dc4-5dcb-b0f3-c89d06ff5e69"
   strings:
      $h1 = "<?xml "
      $x1 = "<machineKey validatio}

Matches rule WEBSHELL_ASP_OBFUSC

195×

Matched Strings

$asp_obf1
50×
Offset (hex) Offset (dec) Length Matched Data
0x52 82 1
0x5A 90 1
0x61 97 1
0x64 100 1
0x68 104 1
0x6B 107 1
0x6F 111 1
0x1F4 500 1
0x549 1353 1
0x5C8 1480 1
0x6A7 1703 1
0x760 1888 1
0xCF5 3317 1
0xDEE 3566 1
0x16CD 5837 1
0x17A1 6049 1
0x17AA 6058 1
0x1951 6481 1
0x1CDA 7386 1
0x1E1D 7709 1
0x1F76 8054 1
0x1F9B 8091 1
0x20A0 8352 1
0x20B1 8369 1
0x20B9 8377 1
0x20EE 8430 1
0x2269 8809 1
0x2272 8818 1
0x2321 8993 1
0x235E 9054 1
0x23F1 9201 1
0x2475 9333 1
0x24F5 9461 1
0x25C2 9666 1
0x25C7 9671 1
0x26A0 9888 1
0x26A6 9894 1
0x26B0 9904 1
0x26CD 9933 1
0x2712 10002 1
0x271C 10012 1
0x27FB 10235 1
0x28B4 10420 1
0x28BC 10428 1
0x28C9 10441 1
0x2912 10514 1
0x2964 10596 1
0x2BD4 11220 1
0x2C2D 11309 1
0x2C63 11363 1
$susasp10
44×
Offset (hex) Offset (dec) Length Matched Data
0x20E91 134801 2 "
0x24237 148023 2 "
0x27D02 163074 2 "
0x52642 337474 2 "
0x6E0DC 450780 2 "
0x99848 628808 2 "
0xAAB5E 699230 2 "
0xBF085 782469 2 "
0xE9704 956164 2 "
0xF0D2F 986415 2 "
0xF708F 1011855 2 "
0x103768 1062760 2 "
0x10F291 1110673 2 "
0x123AC0 1194688 2 "
0x12570D 1201933 2 "
0x128142 1212738 2 "
0x170CE0 1510624 2 "
0x175291 1528465 2 "
0x17A4DF 1549535 2 "
0x18BF50 1621840 2 "
0x1B83DF 1803231 2 "
0x1DCDDB 1953243 2 "
0x1F20CD 2040013 2 "
0x1FC298 2081432 2 "
0x2020AC 2105516 2 "
0x21EBD6 2223062 2 "
0x221D08 2235656 2 "
0x222A06 2238982 2 "
0x22E8D4 2287828 2 "
0x2349B2 2312626 2 "
0x257F40 2457408 2 "
0x270CB7 2559159 2 "
0x2719FB 2562555 2 "
0x28717A 2650490 2 "
0x29845C 2720860 2 "
0x2D569A 2971290 2 "
0x325501 3298561 2 "
0x34C718 3458840 2 "
0x34DACC 3463884 2 "
0x3996C1 3774145 2 "
0x39DF60 3792736 2 "
0x3A8A9A 3836570 2 "
0x3D7BCA 4029386 2 "
0x3F5791 4151185 2 "
$tagasp_short2
50×
Offset (hex) Offset (dec) Length Matched Data
0x134D4 79060 2 %>
0x32F94 208788 2 %>
0x50371 328561 2 %>
0x57F35 360245 2 %>
0x5A32E 369454 2 %>
0x6C430 443440 2 %>
0x6FD3E 458046 2 %>
0x74D29 478505 2 %>
0x84D25 544037 2 %>
0xA4F45 675653 2 %>
0xC9A6E 825966 2 %>
0xD10AC 856236 2 %>
0xD5C3D 875581 2 %>
0xDD920 907552 2 %>
0xEC776 968566 2 %>
0x112DB4 1125812 2 %>
0x11B13B 1159483 2 %>
0x12B5AB 1226155 2 %>
0x17546C 1528940 2 %>
0x17C9E9 1559017 2 %>
0x1806D4 1574612 2 %>
0x1851CE 1593806 2 %>
0x188863 1607779 2 %>
0x193A2E 1653294 2 %>
0x1A023A 1704506 2 %>
0x1A37D1 1718225 2 %>
0x1AB824 1751076 2 %>
0x1AB83C 1751100 2 %>
0x1BBE40 1818176 2 %>
0x1C7D78 1867128 2 %>
0x1E6E05 1994245 2 %>
0x1E778F 1996687 2 %>
0x219C7B 2202747 2 %>
0x21D3B5 2216885 2 %>
0x22534A 2249546 2 %>
0x231367 2298727 2 %>
0x235ED9 2318041 2 %>
0x236035 2318389 2 %>
0x24931D 2396957 2 %>
0x28A9CA 2664906 2 %>
0x292BA3 2698147 2 %>
0x29CB63 2739043 2 %>
0x29DE40 2743872 2 %>
0x29F891 2750609 2 %>
0x2B161F 2823711 2 %>
0x2DE389 3007369 2 %>
0x306DA5 3173797 2 %>
0x308C28 3181608 2 %>
0x314AF2 3230450 2 %>
0x315BBA 3234746 2 %>
$tagasp_short1
50×
Offset (hex) Offset (dec) Length Matched Data
0x418D6 268502 3 <%\xDF
0x65FC0 417728 3 <%\x0B
0x80DD0 527824 3 <%!
0x8B8C2 571586 3 <%9
0x9A4AA 631978 3 <%\x87
0xA82F7 688887 3 <%\xE1
0xAB6E1 702177 3 <%\xE4
0xEE9CA 977354 3 <%\xA0
0x10DB27 1104679 3 <%]
0x134654 1263188 3 <%
0x13A13E 1286462 3 <%7
0x14ACA0 1354912 3 <%\xE1
0x14CD9C 1363356 3 <%k
0x159DDF 1416671 3 <%\xC7
0x163B98 1457048 3 <%\xEB
0x1A692F 1730863 3 <%*
0x1A9D7E 1744254 3 <%9
0x1B3DCC 1785292 3 <%\xBD
0x1BDA1C 1825308 3 <%\x99
0x1C2FEF 1847279 3 <%e
0x1D70D3 1929427 3 <%\x8F
0x1E66E8 1992424 3 <%\xFD
0x1E7388 1995656 3 <%\xF1
0x1E7E85 1998469 3 <%)
0x1ED1BC 2019772 3 <%\xC7
0x1FAC2A 2075690 3 <%3
0x2102A0 2163360 3 <%\x95
0x21C000 2211840 3 <%.
0x2205BB 2229691 3 <%\x80
0x2331DD 2306525 3 <%\xD6
0x243F53 2375507 3 <%\x0D
0x266256 2515542 3 <%\xC8
0x26E4BA 2548922 3 <%\xF3
0x279482 2593922 3 <%\x08
0x28DC5A 2677850 3 <%\xF9
0x2BB6AA 2864810 3 <%@
0x2BCA67 2869863 3 <%\x04
0x2C7A16 2914838 3 <%5
0x2ECD17 3067159 3 <%F
0x2FE667 3139175 3 <%\xF8
0x304D70 3165552 3 <%\xE5
0x3064DE 3171550 3 <%?
0x30A131 3186993 3 <%\xD5
0x32200B 3285003 3 <%T
0x3288D1 3311825 3 <%\x1F
0x33E3C1 3400641 3 <%\xE0
0x34B497 3454103 3 <%?
0x34DAEA 3463914 3 <%\x8D
0x35431C 3490588 3 <%\xBF
0x374056 3620950 3 <%E
$tagasp_long11
Offset (hex) Offset (dec) Length Matched Data
0x134654 1263188 4 <% o

Matches rule WEBSHELL_ASP_Writer

102×

Matched Strings

$tagasp_short2
50×
Offset (hex) Offset (dec) Length Matched Data
0x134D4 79060 2 %>
0x32F94 208788 2 %>
0x50371 328561 2 %>
0x57F35 360245 2 %>
0x5A32E 369454 2 %>
0x6C430 443440 2 %>
0x6FD3E 458046 2 %>
0x74D29 478505 2 %>
0x84D25 544037 2 %>
0xA4F45 675653 2 %>
0xC9A6E 825966 2 %>
0xD10AC 856236 2 %>
0xD5C3D 875581 2 %>
0xDD920 907552 2 %>
0xEC776 968566 2 %>
0x112DB4 1125812 2 %>
0x11B13B 1159483 2 %>
0x12B5AB 1226155 2 %>
0x17546C 1528940 2 %>
0x17C9E9 1559017 2 %>
0x1806D4 1574612 2 %>
0x1851CE 1593806 2 %>
0x188863 1607779 2 %>
0x193A2E 1653294 2 %>
0x1A023A 1704506 2 %>
0x1A37D1 1718225 2 %>
0x1AB824 1751076 2 %>
0x1AB83C 1751100 2 %>
0x1BBE40 1818176 2 %>
0x1C7D78 1867128 2 %>
0x1E6E05 1994245 2 %>
0x1E778F 1996687 2 %>
0x219C7B 2202747 2 %>
0x21D3B5 2216885 2 %>
0x22534A 2249546 2 %>
0x231367 2298727 2 %>
0x235ED9 2318041 2 %>
0x236035 2318389 2 %>
0x24931D 2396957 2 %>
0x28A9CA 2664906 2 %>
0x292BA3 2698147 2 %>
0x29CB63 2739043 2 %>
0x29DE40 2743872 2 %>
0x29F891 2750609 2 %>
0x2B161F 2823711 2 %>
0x2DE389 3007369 2 %>
0x306DA5 3173797 2 %>
0x308C28 3181608 2 %>
0x314AF2 3230450 2 %>
0x315BBA 3234746 2 %>
$asp_text1
Offset (hex) Offset (dec) Length Matched Data
0x1D0 464 5 .text
$tagasp_short1
50×
Offset (hex) Offset (dec) Length Matched Data
0x418D6 268502 3 <%\xDF
0x65FC0 417728 3 <%\x0B
0x80DD0 527824 3 <%!
0x8B8C2 571586 3 <%9
0x9A4AA 631978 3 <%\x87
0xA82F7 688887 3 <%\xE1
0xAB6E1 702177 3 <%\xE4
0xEE9CA 977354 3 <%\xA0
0x10DB27 1104679 3 <%]
0x134654 1263188 3 <%
0x13A13E 1286462 3 <%7
0x14ACA0 1354912 3 <%\xE1
0x14CD9C 1363356 3 <%k
0x159DDF 1416671 3 <%\xC7
0x163B98 1457048 3 <%\xEB
0x1A692F 1730863 3 <%*
0x1A9D7E 1744254 3 <%9
0x1B3DCC 1785292 3 <%\xBD
0x1BDA1C 1825308 3 <%\x99
0x1C2FEF 1847279 3 <%e
0x1D70D3 1929427 3 <%\x8F
0x1E66E8 1992424 3 <%\xFD
0x1E7388 1995656 3 <%\xF1
0x1E7E85 1998469 3 <%)
0x1ED1BC 2019772 3 <%\xC7
0x1FAC2A 2075690 3 <%3
0x2102A0 2163360 3 <%\x95
0x21C000 2211840 3 <%.
0x2205BB 2229691 3 <%\x80
0x2331DD 2306525 3 <%\xD6
0x243F53 2375507 3 <%\x0D
0x266256 2515542 3 <%\xC8
0x26E4BA 2548922 3 <%\xF3
0x279482 2593922 3 <%\x08
0x28DC5A 2677850 3 <%\xF9
0x2BB6AA 2864810 3 <%@
0x2BCA67 2869863 3 <%\x04
0x2C7A16 2914838 3 <%5
0x2ECD17 3067159 3 <%F
0x2FE667 3139175 3 <%\xF8
0x304D70 3165552 3 <%\xE5
0x3064DE 3171550 3 <%?
0x30A131 3186993 3 <%\xD5
0x32200B 3285003 3 <%T
0x3288D1 3311825 3 <%\x1F
0x33E3C1 3400641 3 <%\xE0
0x34B497 3454103 3 <%?
0x34DAEA 3463914 3 <%\x8D
0x35431C 3490588 3 <%\xBF
0x374056 3620950 3 <%E
$tagasp_long11
Offset (hex) Offset (dec) Length Matched Data
0x134654 1263188 4 <% o

Matches rule WEBSHELL_PHP_OBFUSC

51×

Matched Strings

$php_short
50×
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 2 <?
0x1771A 96026 2 <?
0x1F562 128354 2 <?
0x23E7C 147068 2 <?
0x2A09C 172188 2 <?
0x2B97C 178556 2 <?
0x2FD3D 195901 2 <?
0x3FCA5 261285 2 <?
0x4EDFD 323069 2 <?
0x5F7D1 391121 2 <?
0x6AEA0 437920 2 <?
0x96C64 617572 2 <?
0xA0358 656216 2 <?
0xAA464 697444 2 <?
0xB08CE 723150 2 <?
0xC1186 790918 2 <?
0xC9136 823606 2 <?
0xCDE87 843399 2 <?
0xCF04B 847947 2 <?
0xD8239 885305 2 <?
0xF8C53 1018963 2 <?
0x132E56 1257046 2 <?
0x13C06C 1294444 2 <?
0x151878 1382520 2 <?
0x15E1B4 1434036 2 <?
0x1648DF 1460447 2 <?
0x165FCD 1466317 2 <?
0x1735DB 1521115 2 <?
0x17B225 1552933 2 <?
0x17C65F 1558111 2 <?
0x185FFC 1597436 2 <?
0x18AC26 1616934 2 <?
0x18E63D 1631805 2 <?
0x1928DF 1648863 2 <?
0x193277 1651319 2 <?
0x19E3F4 1696756 2 <?
0x19ECC4 1699012 2 <?
0x1A2B7E 1715070 2 <?
0x1A7A33 1735219 2 <?
0x1BFC91 1834129 2 <?
0x1D45B1 1918385 2 <?
0x1DBA52 1948242 2 <?
0x1DF5B5 1963445 2 <?
0x1E1F2B 1974059 2 <?
0x1F1889 2037897 2 <?
0x1F75FB 2061819 2 <?
0x22B341 2274113 2 <?
0x230D2E 2297134 2 <?
0x2443DB 2376667 2 <?
0x24C90A 2410762 2 <?
$no_xml1
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 13 <?xml version

Matches rule WEBSHELL_PHP_OBFUSC_Tiny

51×

Matched Strings

$php_short
50×
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 2 <?
0x1771A 96026 2 <?
0x1F562 128354 2 <?
0x23E7C 147068 2 <?
0x2A09C 172188 2 <?
0x2B97C 178556 2 <?
0x2FD3D 195901 2 <?
0x3FCA5 261285 2 <?
0x4EDFD 323069 2 <?
0x5F7D1 391121 2 <?
0x6AEA0 437920 2 <?
0x96C64 617572 2 <?
0xA0358 656216 2 <?
0xAA464 697444 2 <?
0xB08CE 723150 2 <?
0xC1186 790918 2 <?
0xC9136 823606 2 <?
0xCDE87 843399 2 <?
0xCF04B 847947 2 <?
0xD8239 885305 2 <?
0xF8C53 1018963 2 <?
0x132E56 1257046 2 <?
0x13C06C 1294444 2 <?
0x151878 1382520 2 <?
0x15E1B4 1434036 2 <?
0x1648DF 1460447 2 <?
0x165FCD 1466317 2 <?
0x1735DB 1521115 2 <?
0x17B225 1552933 2 <?
0x17C65F 1558111 2 <?
0x185FFC 1597436 2 <?
0x18AC26 1616934 2 <?
0x18E63D 1631805 2 <?
0x1928DF 1648863 2 <?
0x193277 1651319 2 <?
0x19E3F4 1696756 2 <?
0x19ECC4 1699012 2 <?
0x1A2B7E 1715070 2 <?
0x1A7A33 1735219 2 <?
0x1BFC91 1834129 2 <?
0x1D45B1 1918385 2 <?
0x1DBA52 1948242 2 <?
0x1DF5B5 1963445 2 <?
0x1E1F2B 1974059 2 <?
0x1F1889 2037897 2 <?
0x1F75FB 2061819 2 <?
0x22B341 2274113 2 <?
0x230D2E 2297134 2 <?
0x2443DB 2376667 2 <?
0x24C90A 2410762 2 <?
$no_xml1
Offset (hex) Offset (dec) Length Matched Data
0x127E8 75752 13 <?xml version

Matches rule WebShell_php_webshells_MyShell

50×

Matched Strings

$s14
50×
Offset (hex) Offset (dec) Length Matched Data
0x1F4 500 1
0xCF5 3317 1
0x16CD 5837 1
0x17A1 6049 1
0x17AA 6058 1
0x1951 6481 1
0x1E1D 7709 1
0x1F76 8054 1
0x1F9B 8091 1
0x20A0 8352 1
0x20EE 8430 1
0x2269 8809 1
0x2272 8818 1
0x235E 9054 1
0x25C2 9666 1
0x25C7 9671 1
0x271C 10012 1
0x27FB 10235 1
0x28B4 10420 1
0x28BC 10428 1
0x2912 10514 1
0x2964 10596 1
0x2C63 11363 1
0x2C76 11382 1
0x2CF1 11505 1
0x3133 12595 1
0x32F6 13046 1
0x3641 13889 1
0x3650 13904 1
0x39ED 14829 1
0x3A16 14870 1
0x3A2B 14891 1
0x40CB 16587 1
0x40D9 16601 1
0x4209 16905 1
0x4297 17047 1
0x4300 17152 1
0x4314 17172 1
0x46BA 18106 1
0x48A7 18599 1
0x49F7 18935 1
0x4C9B 19611 1
0x4CAB 19627 1
0x5117 20759 1
0x54F3 21747 1
0x55ED 21997 1
0x59CD 22989 1
0x5A47 23111 1
0x5A96 23190 1
0x5B11 23313 1

Matches rule svchost_ANOMALY from malware

Abnormal svchost.exe - typical strings not found in file

Matched Strings

$win2003_win7_u3
Offset (hex) Offset (dec) Length Matched Data
0x127CA 75722 22 T\x00r\x00a\x00n\x00s\x00l\x00a\x00t\x00i\x00o\x00n\x00
$win2003_win7_u4
Offset (hex) Offset (dec) Length Matched Data
0x127AA 75690 22 V\x00a\x00r\x00F\x00i\x00l\x00e\x00I\x00n\x00f\x00o\x00
rule svchost_ANOMALY
{4/2014"
      score = 55
      nodeepdive = 1
      id = "ea436608-d191-5058-b844-025e48082edc"
   strings:
      $win2003_win7_u1 = "IEXPLORE.EXE" wide nocase
      $win2003_win7_u2 = "Internet Explorer" wide fullword
      $win2003_win7_u3 = "translation" wide fullword nocase
      $win2003_win7_u4 = "varfileinfo" wide fullword nocase
   condition:
      filename == "iexplore.exe"
      and uint16(0) == 0x5a4d
      and not filepath contains "teamviewer"
      and not 1 of ($win*) and not WINDOWS_UPDATE_BDC
      and filepath contains "C:\\"
      and not filepath contains "Package_for_RollupFix"
}

rule svchost_ANOMALY {
	meta:
		license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
		author = "Florian Roth (Nextron Systems)"
		description = "Abnormal svchost.exe - typical strings not found in file"
		date = "23/04/2014"
		score = 55
		id = "5630054d-9fa4-587f-ba78-cda4478f9cc1"
	strings:
		$win2003_win7_u1 = "svchost.exe" wide nocase
		$win2003_win7_u3 = "coinitializesecurityparam" wide fullword nocase
		$win2003_win7_u4 = "servicedllunloadonstop" wide fullword nocase
		$win2000 = "Generic Host Process for Win32 Services" wide fullword
		$win2012 = "Host Process for Windows Serv}

Hashes

SHA-256

bea2ca4c9d9abd1ff214166d638792be974ffad7907a8a8ed0370acba800e815

SHA-1

c8ca0643693fbca5cda17886f478666ff0d35cee

MD5

e27d92658cebb4eabea7e74125464023

SHA-512

77e261afda1eed9ab1fb38d446a08f58fb7c8546aac319565c61a36805c040637f69b20d91521d7f6ea4e8ca571ba372d7ace9f115c03c39d2f3c9131cfc8a57

File Properties

Detected Type Windows Executable (PE)
Magic PE32 executable for MS Windows 4.00 (GUI), Intel i386, Nullsoft Installer self-extracting archive, 5 sections
Client MIME application/vnd.microsoft.portable-executable
Size 4 MB
Entropy 7.991 / 8.0
possibly packed
Times Analyzed 1
First Analyzed Aug 9, 2026 18:34
Last Analyzed Aug 9, 2026 18:34

Executable (PE) Details

Machine x86 (32-bit)
Bitness 32-bit (PE32)
Subsystem Windows GUI
Compiled 2016-12-11 21:50:52 UTC
Entry Point 0x31A3
Type EXE
Imphash b78ecf47c0a3e24a6f4af114e2d1f5de
Imported DLLs 7
Imported Functions 85
Digitally signed
Section Virtual Size Raw Size Entropy
.text 24689 25088 6.43
.rdata 4946 5120 5.24
.data 152824 1536 4.04
.ndata 98304 0
.rsrc 44056 44544 3.02
Imported DLLs (7)
KERNEL32.dll — 25 function(s)
USER32.dll — 25 function(s)
GDI32.dll — 8 function(s)
SHELL32.dll — 6 function(s)
ADVAPI32.dll — 13 function(s)
COMCTL32.dll — 4 function(s)
ole32.dll — 4 function(s)

Extracted IOCs

6 indicator(s) found in file content
IP Address
2
1.0.0.0 6.0.0.0
URL
1
http://nsis.sf.net/NSIS_Error
Domain
3
Nullsoft.NSIS.exehead Microsoft.Windows.Common Vm.QDw

Static Strings

500 strings · printable ASCII ≥ 6 chars
Offset (hex) Offset (dec) String
0x4D 77 !This program cannot be run in DOS mode.
0x1F7 503 `.rdata
0x21F 543 @.data
0x248 584 .ndata
0x6A7 1703 s495,
0x1803 6147 SQSSSPW
0x21E2 8674 Instu`
0x21EB 8683 softuW
0x21F4 8692 NulluN
0x29F3 10739 D$$Ph,
0x2A06 10758 D$(SPS
0x2A32 10802 Vj%SSS
0x2CFD 11517 D$$+D$
0x2D08 11528 D$,+D$$P
0x56E9 22249 HtVHtHH
0x6898 26776 UXTHEME
0x68A0 26784 USERENV
0x68A8 26792 SETUPAPI
0x68B1 26801 APPHELP
0x68B9 26809 PROPSYS
0x68C1 26817 DWMAPI
0x68C8 26824 CRYPTBASE
0x68D2 26834 OLEACC
0x68D9 26841 CLBCATQ
0x68E4 26852 RichEdit
0x68F0 26864 RichEdit20A
0x68FC 26876 RichEd32
0x6908 26888 RichEd20
0x6914 26900 .DEFAULT\Control Panel\International
0x693C 26940 Control Panel\Desktop\ResourceLocale
0x69A0 27040 Software\Microsoft\Windows\CurrentVersion
0x69CC 27084 \Microsoft\Internet Explorer\Quick Launch
0x6E6E 28270 MulDiv
0x6E78 28280 DeleteFileA
0x6E86 28294 FindFirstFileA
0x6E98 28312 FindNextFileA
0x6EA8 28328 FindClose
0x6EB4 28340 SetFilePointer
0x6EC6 28358 GetPrivateProfileStringA
0x6EE2 28386 WritePrivateProfileStringA
0x6F00 28416 MultiByteToWideChar
0x6F16 28438 FreeLibrary
0x6F24 28452 LoadLibraryExA
0x6F36 28470 GetModuleHandleA
0x6F4A 28490 GetExitCodeProcess
0x6F60 28512 WaitForSingleObject
0x6F76 28534 GlobalAlloc
0x6F84 28548 GlobalFree
0x6F92 28562 ExpandEnvironmentStringsA
0x6FAE 28590 lstrcmpA
0x6FBA 28602 lstrcmpiA
0x6FC6 28614 CloseHandle
0x6FD4 28628 SetFileTime
0x6FE2 28642 CompareFileTime
0x6FF4 28660 SearchPathA
0x7002 28674 GetShortPathNameA
0x7016 28694 GetFullPathNameA
0x702A 28714 MoveFileA
0x7036 28726 SetCurrentDirectoryA
0x704E 28750 GetFileAttributesA
0x7064 28772 SetFileAttributesA
0x7082 28802 GetTickCount
0x7092 28818 GetFileSize
0x70A0 28832 GetModuleFileNameA
0x70B6 28854 GetCurrentProcess
0x70CA 28874 CopyFileA
0x70D6 28886 ExitProcess
0x70E4 28900 SetEnvironmentVariableA
0x70FE 28926 GetWindowsDirectoryA
0x7116 28950 GetTempPathA
0x7126 28966 GetCommandLineA
0x7138 28984 lstrlenA
0x7144 28996 GetVersion
0x7152 29010 SetErrorMode
0x7162 29026 lstrcpynA
0x716E 29038 GetDiskFreeSpaceA
0x7182 29058 GlobalUnlock
0x7192 29074 GlobalLock
0x71A0 29088 CreateThread
0x71B0 29104 GetLastError
0x71C0 29120 CreateDirectoryA
0x71D4 29140 CreateProcessA
0x71E6 29158 RemoveDirectoryA
0x71FA 29178 CreateFileA
0x7208 29192 GetTempFileNameA
0x721C 29212 ReadFile
0x7228 29224 WriteFile
0x7234 29236 lstrcpyA
0x7240 29248 MoveFileExA
0x724E 29262 lstrcatA
0x725A 29274 GetSystemDirectoryA
0x7270 29296 GetProcAddress
0x7280 29312 KERNEL32.dll
0x7290 29328 EndPaint
0x729C 29340 DrawTextA
0x72A8 29352 FillRect
0x72B4 29364 GetClientRect
0x72C4 29380 BeginPaint
0x72D2 29394 DefWindowProcA
0x72E4 29412 SendMessageA
0x72F4 29428 InvalidateRect
0x7306 29446 EnableWindow
0x7316 29462 ReleaseDC
0x732A 29482 LoadImageA
0x7338 29496 SetWindowLongA
0x734A 29514 GetDlgItem
0x7358 29528 IsWindow
0x7364 29540 FindWindowExA
0x7374 29556 SendMessageTimeoutA
0x738A 29578 wsprintfA
0x7396 29590 ShowWindow
0x73A4 29604 SetForegroundWindow
0x73BA 29626 PostQuitMessage
0x73CC 29644 SetWindowTextA
0x73DE 29662 SetTimer
0x73EA 29674 CreateDialogParamA
0x7400 29696 DestroyWindow
0x7410 29712 ExitWindowsEx
0x7420 29728 CharNextA
0x742C 29740 DialogBoxParamA
0x743E 29758 GetClassInfoA
0x744E 29774 CreateWindowExA
0x7460 29792 SystemParametersInfoA
0x7478 29816 RegisterClassA
0x748A 29834 EndDialog
0x7496 29846 ScreenToClient
0x74A8 29864 GetWindowRect
0x74B8 29880 EnableMenuItem
0x74CA 29898 GetSystemMenu
0x74DA 29914 SetClassLongA
0x74EA 29930 IsWindowEnabled
0x74FC 29948 SetWindowPos
0x750C 29964 GetSysColor
0x751A 29978 GetWindowLongA
0x752C 29996 SetCursor
0x7538 30008 LoadCursorA
0x7546 30022 CheckDlgButton
0x7558 30040 GetMessagePos
0x7568 30056 LoadBitmapA
0x7576 30070 CallWindowProcA
0x7588 30088 IsWindowVisible
0x759A 30106 CloseClipboard
0x75AC 30124 SetClipboardData
0x75C0 30144 EmptyClipboard
0x75D2 30162 OpenClipboard
0x75E2 30178 TrackPopupMenu
0x75F4 30196 AppendMenuA
0x7602 30210 CreatePopupMenu
0x7614 30228 GetSystemMetrics
0x7628 30248 SetDlgItemTextA
0x763A 30266 GetDlgItemTextA
0x764C 30284 MessageBoxIndirectA
0x7662 30306 CharPrevA
0x766E 30318 DispatchMessageA
0x7682 30338 PeekMessageA
0x7690 30352 USER32.dll
0x769E 30366 SelectObject
0x76AE 30382 SetTextColor
0x76BE 30398 SetBkMode
0x76CA 30410 CreateFontIndirectA
0x76E0 30432 CreateBrushIndirect
0x76F6 30454 DeleteObject
0x7706 30470 GetDeviceCaps
0x7716 30486 SetBkColor
0x7722 30498 GDI32.dll
0x772E 30510 SHFileOperationA
0x7742 30530 ShellExecuteA
0x7752 30546 SHGetFileInfoA
0x7764 30564 SHBrowseForFolderA
0x777A 30586 SHGetPathFromIDListA
0x7792 30610 SHGetSpecialFolderLocation
0x77AE 30638 SHELL32.dll
0x77BC 30652 RegEnumValueA
0x77CC 30668 RegEnumKeyA
0x77DA 30682 RegQueryValueExA
0x77EE 30702 RegSetValueExA
0x7800 30720 RegCreateKeyExA
0x7812 30738 RegCloseKey
0x7820 30752 RegDeleteValueA
0x7832 30770 RegDeleteKeyA
0x7842 30786 RegOpenKeyExA
0x7852 30802 AdjustTokenPrivileges
0x786A 30826 LookupPrivilegeValueA
0x7882 30850 OpenProcessToken
0x7896 30870 SetFileSecurityA
0x78A8 30888 ADVAPI32.dll
0x78B8 30904 ImageList_Destroy
0x78CC 30924 ImageList_AddMasked
0x78E2 30946 ImageList_Create
0x78F4 30964 COMCTL32.dll
0x7904 30980 CoCreateInstance
0x7918 31000 OleUninitialize
0x792A 31018 OleInitialize
0x793A 31034 CoTaskMemFree
0x7948 31048 ole32.dll
0x7A1C 31260 verifying installer: %d%%
0x7A38 31288 Installer integrity check has failed. Common causes include
0x7A74 31348 incomplete download and damaged media. Contact the
0x7AA7 31399 installer's author to obtain a new copy.
0x7AD1 31441 More information at:
0x7AE6 31462 http://nsis.sf.net/NSIS_Error
0x7B04 31492 Error launching installer
0x7B20 31520 ... %d%%
0x7B2C 31532 SeShutdownPrivilege
0x7B88 31624 NSIS Error
0x7B98 31640 Error writing temporary file. Make sure your temp folder is valid.
0x7C08 31752 %u.%u%s%s
0x7C98 31896 VerQueryValueA
0x7CA8 31912 GetFileVersionInfoA
0x7CBC 31932 GetFileVersionInfoSizeA
0x7CD4 31956 VERSION
0x7CDC 31964 SHGetFolderPathA
0x7CF0 31984 SHFOLDER
0x7CFC 31996 SHAutoComplete
0x7D0C 32012 SHLWAPI
0x7D14 32020 SHELL32
0x7D1C 32028 InitiateShutdownA
0x7D30 32048 RegDeleteKeyExA
0x7D40 32064 ADVAPI32
0x7D4C 32076 GetUserDefaultUILanguage
0x7D68 32104 GetDiskFreeSpaceExA
0x7D7C 32124 SetDefaultDllDirectories
0x7D98 32152 KERNEL32
0x7DB4 32180 [Rename]
0x7DCC 32204 *?|<>/":
0x7DD8 32216 %s%s.dll
0x127E8 75752 <?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="Null
0x12E08 77320 NullsoftInst
0x134A9 79017 -2#3>Om
0x141CB 82379 ~9Ex>{
0x145DD 83421 pQ@hDc
0x1464C 83532 %7,2B13
0x14748 83784 *PnFK"z3h*\
0x148BF 84159 76e^\X
0x14A13 84499 ~EMuuEy`
0x14BCD 84941 ,/)S\N
0x14D95 85397 74rxxD
0x15201 86529 >zz(uL
0x15268 86632 6DO7-Mb
0x1568B 87691 ] 6)w)_
0x15896 88214 DLka`_
0x159E8 88552 0$Mu`w
0x15BB4 89012 Qr`^ya
0x15C12 89106 :2:!R#
0x15D5F 89439 ?> 8Po`
0x160EF 90351 d2L1q=
0x166BF 91839 }tJ'hr
0x16891 92305 N_zzY,Q
0x16998 92568 pyK#,@1
0x16AFD 92925 0b1&51'n4S
0x16B8D 93069 \XOFP<
0x16DAD 93613 $\j\s-
0x16EE4 93924 TO$AGf
0x173BA 95162 fvr)sU
0x17797 96151 jh{JTpS
0x17B3C 97084 E29a[Xd&
0x17C71 97393 I_3K>U
0x17CB2 97458 WifRVfr
0x17E06 97798 t.QG5fzHk$7.
0x17F5E 98142 )!pvwT`
0x180C7 98503 rM2+Us
0x1814C 98636 Wgy2FO^Q
0x1839F 99231 1T:D)]3l
0x18545 99653 gYq%o;
0x1896A 100714 ]yymkn
0x18A91 101009 A`f5VS8
0x18D86 101766 aZIJq%
0x18E07 101895 cynjN?
0x193AE 103342 ]Ede;|
0x19638 103992 =;8U/3
0x19B65 105317 ?D-.iq
0x19C68 105576 uz?H{A
0x19CA9 105641 pN`1Gf[
0x19D22 105762 *H@6]U."
0x19D4D 105805 Lhe~(6I
0x1A116 106774 P\QYq}
0x1A12A 106794 J(.\]qkQ
0x1A1E9 106985 KqDZkQE
0x1A2A2 107170 f1%7$)r
0x1A61F 108063 0aHFB)]
0x1AF9E 110494 ^gA&bC
0x1B111 110865 nqeIUUpQIyuIz
0x1B139 110905 U%5UbAEeyIQIq
0x1B1A7 111015 8XY]ZTS
0x1B245 111173 (.]PZD'
0x1B270 111216 P~_3;&z
0x1B34E 111438 uQEeep
0x1B465 111717 !l4'#u
0x1B491 111761 +x+_ja4Qe
0x1B92B 112939 Mhgz@J
0x1BACF 113359 }}b%rr
0x1C129 114985 W?zk(9
0x1C3DD 115677 iL?lM4|J
0x1C47C 115836 iy^l}(u
0x1C542 116034 u}08>x
0x1C74A 116554 " )_@A
0x1CC04 117764 t852qb
0x1D244 119364 O)?Y:s
0x1D2F8 119544 D)uScc
0x1D316 119574 ?qd^E8TQ
0x1D539 120121 +.&!a72
0x1DC3B 121915 >:~zl4?
0x1E0E3 123107 W 6rPkt@
0x1E1E3 123363 :Fn}U]ze;
0x1E281 123521 {$4$~l
0x1E30A 123658 |{(;.l?
0x1E3FB 123899 %/ASnt#
0x1E47A 124026 ?S23aGf
0x1E716 124694 c18~p85
0x1E939 125241 F<aFECoK"q
0x1E9B7 125367 TUU,.]T
0x1EA8E 125582 vMZDKb+
0x1EBDF 125919 ,!_#6JF5
0x1ECAA 126122 6mV$*w0
0x1EF3C 126780 @GDMRH
0x1EF9B 126875 vhjP>T
0x1F0F8 127224 ^sE2l+
0x1F3C6 127942 suMEuu
0x1F3E4 127972 x#v)%$
0x1F96A 129386 %WRXH1G
0x1F9E2 129506 L=kyic
0x1FBAB 129963 )Ziv 0C
0x1FBBE 129982 ~%lVYM
0x1FE8F 130703 `*0LJVd\
0x20165 131429 lljN47'%
0x201F1 131569 6k57&k
0x202A7 131751 i5cwHDG
0x20400 132096 l~.U.O
0x20A39 133689 @R+uQ2
0x20C36 134198 !wl<|9~g
0x20C68 134248 DqF8Sy
0x20C88 134280 af}eXB
0x20DDF 134623 NN'WkyA
0x20E8D 134797 rG(3 "z
0x20F8A 135050 \+.565
0x21165 135525 xU6Re,
0x212DF 135903 7ssi/'
0x21407 136199 P-7kT<
0x2147E 136318 mTK(>!
0x21AE0 137952 \CAP8O
0x21BDE 138206 M4.O>W
0x21C76 138358 <]otsZat
0x21D79 138617 O|@`v~J
0x21EE0 138976 ,IbZa<
0x21F52 139090 #5R9ea
0x21F63 139107 c8KRD6Q
0x2207D 139389 'Vm.QDw?Pm
0x225AF 140719 k\4lhAYi{Rd
0x22E31 142897 T&dBX!
0x2304A 143434 L-]e59!
0x231FB 143867 ERd|7,
0x2329C 144028 g~<l8G
0x23376 144246 ~qud/}
0x2354E 144718 P:Zag>L
0x238BA 145594 PE4ljj
0x239EF 145903 |$&khj
0x23C98 146584 9$f%C$G
0x24070 147568 kF;oM>
0x240E7 147687 [04!6\
0x241B1 147889 9<pH$Vd
0x2425D 148061 JX@](;
0x2433E 148286 x,bsHI
0x24A6B 150123 m2TP3d
0x24A89 150153 O|5qSi
0x24D35 150837 ;4AbKqWn
0x24F7A 151418 v?I\`u
0x25456 152662 X#,?pl
0x256E1 153313 fj/:+I
0x25A00 154112 :5x~;F
0x25C58 154712 VanBZN
0x25CF1 154865 |% L|1|p
0x2651E 156958 &*A$L\m
0x26A0E 158222 \~Mdoy
0x26CC2 158914 dMmCS\
0x26D1B 159003 Q_II+4
0x26E07 159239 [jYVqY%m
0x27797 161687 1~8yFS
0x277D7 161751 B!q4:hN
0x27969 162153 K+.X=[lgAV>
0x27A34 162356 Eh?$H]
0x27A6E 162414 e8(~Q=`e
0x27B5B 162651 lADV#6
0x27CFE 163070 b:t2 "x
0x27D4A 163146 t>'fhK.
0x27EE6 163558 XIjUe8
0x27F37 163639 b_XYq;[
0x28377 164727 ]TZAA/
0x286C0 165568 b3oF5q
0x28AAA 166570 Z@l(PDBR
0x28F55 167765 s';/'W%
0x292DB 168667 Zts|G0o
0x2A008 172040 A+>lJpATJg
0x2A77E 173950 CbTbo}%
0x2AFA6 176038 J?ue`*b8
0x2AFE5 176101 tlxrtwl
0x2B129 176425 NY!\h=sV
0x2B5A0 177568 YRhMKFU
0x2B5CE 177614 @#[Rz^
0x2BAD0 178896 ^|BtAf
0x2BC9A 179354 FK7s;_(K
0x2BEDC 179932 u(!Ef=
0x2C127 180519 ACS$eP
0x2D550 185680 EW*fdr
0x2DAD2 187090 G9#4tKv
0x2DB53 187219 b/ACs\8
0x2DD9E 187806 ycO@e-
0x2DE16 187926 Ctv"Ws
0x2E440 189504 'Xm7pk
0x2E57B 189819 /94oL"zb
0x2E741 190273 +XTPRP^
0x2E7B2 190386 Aoq&<hsz
0x2E7EF 190447 j@0.d&C
0x2E82D 190509 M-\Xy%0
0x2E8CE 190670 AS9a"^pW
0x2EB89 191369 40^WN1
0x2ED13 191763 R'BKY[
0x2EFDA 192474 %\9C`'
0x2F973 194931 MECPTd
0x2FEE8 196328 6HN$(m
0x30824 198692 <d,e?Q
0x30855 198741 <Q*2v=
0x3085C 198748 Wi|{?p
0x315D7 202199 ]WF!Vh
0x31E56 204374 G:+)(-
0x31F6B 204651 ~iP_o;
0x32009 204809 #\mg4EE
0x3211B 205083 z}(sP}
0x3219A 205210 5VUl~rYT
0x32823 206883 L,1AwTv
0x32C64 207972 HB46~w
0x32D62 208226 \{Rwf|
0x32E9E 208542 A+&~$g
0x32EC2 208578 FiITIQ:
0x32F77 208759 IPa<UW
0x33143 209219 0~\?xv
0x332BF 209599 Jxo&A79
0x332E4 209636 U@-(B)
0x336D3 210643 | YxL,
0x33820 210976 +ug9#i
0x338F0 211184 :v.0.s
0x33C85 212101 NC5SY-ngf
0x3400D 213005 jmox5}I
0x34481 214145 8a7%:]
0x347F2 215026 $B(k}|
0x34C38 216120 8KM&Yj
0x3505A 217178 yW)A^u
0x35129 217385 ` 8/s8
0x351DA 217562 d7zy{&
0x35BD6 220118 dOSsNEW2
0x35FB5 221109 72ejb29A0
0x3610B 221451 yFax-4}zRa}dW
0x36209 221705 -]_c1$
0x364E9 222441 [!'I5=
0x3667C 222844 yF,Pia3
0x36D4A 224586 y&yz/(
0x36DE8 224744 MOlF$[
0x36F75 225141 5K"0stui
0x37185 225669 8P"J%&
0x3727E 225918 />sBQl%
0x374BB 226491 X^nkY5
0x374E3 226531 j+5z?,/
0x37650 226896 Ogt((~
0x3768B 226955 ,u#t}@Q4g
0x379B7 227767 5Kk$^A
0x37A8E 227982 y8r8C;y
0x37D94 228756 C2]}Ue
0x37E7F 228991 k!Ac#=u
0x383C7 230343 4,`@W2A
0x386FF 231167 f7yi~1
0x38A13 231955 zb]$U9
0x38C32 232498 #WD-2[Ka
0x38C91 232593 <CkiF_
0x38CE3 232675 QYmbeKhT
0x38E6D 233069 -Y]Pt4t
0x38F28 233256 y,?HfJ<C
0x38FA6 233382 pOVZU/
0x392B3 234163 y6{3%ft2X
0x39624 235044 :t'*L:
0x397D8 235480 wtn%od9
0x39DA6 236966 9ak6o8
0x39F3B 237371 K$-qfJ6
0x39FF7 237559 KwnTMc
0x3A011 237585 3WMBGs
0x3A2B3 238259 4,77'Gq
0x3A359 238425 53e#Z_zI
0x3A465 238693 AXv(!'
0x3A4FD 238845 LiN;=6
0x3A544 238916 |w+Z&ot
0x3A799 239513 DZaqO=F
0x3A93D 239933 v28W/$
0x3AB6B 240491 (B;FiG&
0x3AC4C 240716 @>N@>S
0x3B290 242320 11l5Lc
0x3B2A3 242339 |1g . |
0x3B4E3 242915 wyG'6`_
0x3BD7F 245119 Y4f1u3,
0x3BD94 245140 vEhSRv
0x3BEA4 245412 .%2^TTWk
0x3C17B 246139 exx1:lT
0x3C1D4 246228 %UYg,r

Request takedown

Explain why this item should be unpublished from the community. A platform admin will review your request.

Reason
Leaving Threaticon

This link opens an external site that isn't part of the platform.