Natalie Zargarov(@NZargarov) 's Twitter Profile Photo


BruteRatel detection based on anti-debugging and anti-hooking techniques along with some NT function hashes.

github.com/rapid7/Rapid7-…

#100DaysOfYara #R7_Labs
BruteRatel detection based on anti-debugging and anti-hooking techniques along with some NT function hashes.

github.com/rapid7/Rapid7-…
account_circle
Jonathan Peters(@cod3nym) 's Twitter Profile Photo

Day 14:
Another rule for a technique. This rule targets the Right-To-Left (RLO) extension spoofing technique.This spoofing also works on VT but only in the GUI, the URL shows the actual file %E2%80%AEfdp.exe

E2 80 AE are the bytes encoding the…

#100DaysOfYara Day 14:
Another rule for a #UnprotectProject technique. This rule targets the Right-To-Left (RLO) extension spoofing technique.This spoofing also works on VT but only in the GUI, the URL shows the actual file %E2%80%AEfdp.exe 

E2 80 AE are the bytes encoding the…
account_circle
ANY.RUN(@anyrun_app) 's Twitter Profile Photo

🎯 Hunt unique samples

💫 Would you like to develop threat hunting rules?

📌 Here is an example of how you can do it for the unknown samples of AdWind ( ), a Java-based with remote access capabilities.

✍️ Just follow these steps:

1⃣…

🎯 Hunt unique #AdWind samples #100DaysofYARA

💫 Would you like to develop threat hunting #YARA rules?

📌 Here is an example of how you can do it for the unknown samples of AdWind (#AlienSpy), a Java-based #MaaS with remote access capabilities.

✍️ Just follow these steps:

1⃣…
account_circle
Matthew Green 🌻(@mgreen27) 's Twitter Profile Photo

I use a similar technique to this querying logs remotely as the rule can then return the whole line for context instead of just the string hit.
Here is a an example looking for a line hit adding in anchors at beginning and end targeting access logs.
Pretty much…

#100daysofYARA I use a similar technique  to this querying logs remotely as the rule can then return the whole line for context instead of just the string hit.
Here is a an  example looking for a line hit adding in anchors at beginning and end targeting access logs. 
Pretty much…
account_circle
Jonathan Peters(@cod3nym) 's Twitter Profile Photo

Day 16:
Today I wrote a rule for the PyArmor python obfuscator. A simple rule checking for common strings used by the obfuscators runtime. Also contributing this to

github.com/cod3nym/detect…

#100DaysOfYara Day 16: 
Today I wrote a rule for the PyArmor python obfuscator. A simple rule checking for common strings used by the obfuscators runtime. Also contributing this to #UnprotectProject

github.com/cod3nym/detect…
account_circle
Thomas Roccia 🤘(@fr0gger_) 's Twitter Profile Photo

I stopped the 🙈 because I got swamped with other work & life but during my stint with the challenge, I released YaraToolkit and DocYara (which, let's just say, took me quite some time to create). 🤓

🛠️YaraToolkit is your all-in-one Yara go-to spot 🌟—from…

I stopped the #100daysofYara 🙈 because I got swamped with other work & life but during my stint with the challenge, I released YaraToolkit and DocYara (which, let's just say, took me quite some time to create). 🤓 

🛠️YaraToolkit is your all-in-one Yara go-to spot 🌟—from…
account_circle
Yashraj Solanki(@RustyNoob619) 's Twitter Profile Photo

All of my rules from the 100DaysofYARA challenge are copied over to my new YARA GitHub repo and also renamed the rule files for easier identification 🐧

Link to Repo: github.com/RustyNoob-619/…

I plan to keep adding to this repo and building it up over the year 💪

All of my #YARA rules from the 100DaysofYARA challenge are copied over to my new YARA GitHub repo and also renamed the rule files for easier identification 🐧

Link to Repo: github.com/RustyNoob-619/… 

I plan to keep adding to this repo and building it up over the year 💪
account_circle
Daniel Mayer(@dan__mayer) 's Twitter Profile Photo

Thanks Greg Lesnewich for my new favorite mug!! What and awesome way to close out . The real reward was the rules you made along the way though, eh?

Thanks @greglesnewich for my new favorite mug!! What and awesome way to close out #100DaysofYara. The real reward was the rules you made along the way though, eh?
account_circle
Mostafa Farghaly(@M4lcode) 's Twitter Profile Photo

This is my first contribution to
𝐃𝐚𝐲 𝟭𝟬: My rule detects 𝗠𝗼𝗿𝘁𝗶𝘀 𝗟𝗼𝗰𝗸𝗲𝗿 ransomware that was first discovered on 29 September 2023 by Gameel Ali 🤘
m4lcode.github.io/malware%20anal…

This is my first contribution to #100DaysOfYARA
𝐃𝐚𝐲 𝟭𝟬: My rule detects 𝗠𝗼𝗿𝘁𝗶𝘀 𝗟𝗼𝗰𝗸𝗲𝗿 ransomware that was first discovered on 29 September 2023 by @MalGamy12 
m4lcode.github.io/malware%20anal…
account_circle
alden(@birchb0y) 's Twitter Profile Photo

wrote a lil helper binja script to clean up the __cstring section of a macho file!

its not always perfect but it generally makes the rev experience nicer (esp for those grinding 🫡)

gist.github.com/ald3ns/bc3bcc6…

wrote a lil helper binja script to clean up the __cstring section of a macho file! 

its not always perfect but it generally makes the rev experience nicer (esp for those grinding #100DaysOfYara 🫡)

gist.github.com/ald3ns/bc3bcc6…
account_circle
Florian Roth(@cyb3rops) 's Twitter Profile Photo

I have created a YARA rule to detect binaries that are signed with a potentially compromised AnyDesk signing certificate

(if the PE header info isn't AnyDesk -> other binaries signed with the compromised cert)


github.com/Neo23x0/signat…

I have created a YARA rule to detect binaries that are signed with a potentially compromised AnyDesk signing certificate 

(if the PE header info isn't AnyDesk -> other binaries signed with the compromised cert)

#100DaysOfYARA #AnyDesk 
github.com/Neo23x0/signat…
account_circle
Isaac(@isashau) 's Twitter Profile Photo

Just completed Yara For Security Analysts! Such an amazing course I'd recommend for anyone looking to learn more about malware analysis and detection!

Thanks for the awesome content Steve YARA Synapse Miller


networkdefense.io/library/yara-f…

Just completed Yara For Security Analysts! Such an amazing course I'd recommend for anyone looking to learn more about malware analysis and detection!

Thanks for the awesome content @stvemillertime 

#100daysofyara 
networkdefense.io/library/yara-f…
account_circle