Skip to content

Commit eca2af0

Browse files
committed
Mobile rules based on Androguard are now deprecated. Folders were renamed. Index regenerated.
1 parent b979e00 commit eca2af0

File tree

113 files changed

+233
-352
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

113 files changed

+233
-352
lines changed

.travis.yml

+16-20
Original file line numberDiff line numberDiff line change
@@ -1,41 +1,37 @@
11
language: c
22
sudo: required
3-
#dist: trusty
3+
44
before_install:
55
- sudo apt-get -qq update
6-
- sudo apt-get install jq
6+
- sudo apt-get install -y \
7+
automake \
8+
libtool \
9+
make \
10+
gcc \
11+
pkg-config \
12+
flex \
13+
bison \
14+
libjansson-dev \
15+
libmagic-dev \
16+
libssl-dev \
17+
jq
718
# Yara
819
- wget $(curl -s https://api.github.com/repos/VirusTotal/yara/releases/latest | jq -r ".tarball_url") -O yara.tar.gz
9-
#- wget $(wget -O - https://api.github.com/repos/VirusTotal/yara/releases/9250110 | jq -r ".tarball_url") -O yara.tar.gz
1020
- mkdir yara
1121
- tar -C yara -xzvf yara.tar.gz --strip-components 1
12-
# Androguard for Yara
13-
- wget https://raw.githubusercontent.com/Koodous/androguard-yara/master/androguard.c -O yara/libyara/modules/androguard.c
14-
- wget https://raw.githubusercontent.com/Koodous/androguard-yara/master/dist/yara-3.7.0/libyara/modules/module_list -O yara/libyara/modules/module_list
15-
- wget https://raw.githubusercontent.com/Koodous/androguard-yara/master/dist/yara-3.7.0/libyara/Makefile.am -O yara/libyara/Makefile.am
16-
# libjansson
17-
- wget http://www.digip.org/jansson/releases/jansson-2.7.tar.gz
18-
- tar -xzvf jansson-2.7.tar.gz
19-
- cd jansson-2.7
20-
- ./configure
21-
- make
22-
- sudo make install
23-
2422
# Compile Yara
2523
- cd ../yara
2624
# Update per issue 176
27-
- sed -i 's/#define RE_MAX_SPLIT_ID 128/#define RE_MAX_SPLIT_ID 255/g' libyara/re.c
25+
- sed -i 's/#define RE_MAX_SPLIT_ID 128/#define RE_MAX_SPLIT_ID 255/g' libyara/include/yara/limits.h
2826
- ./bootstrap.sh
29-
- ./configure --enable-cuckoo
27+
- ./configure --enable-cuckoo --enable-magic --with-crypto
3028
- make
3129
- sudo make install
3230
- sudo ldconfig
3331
- cd ../
3432

3533
script:
3634
- echo "test" > testfile
37-
- echo "{}" > androguard_report.json
3835
- FALLO=0
39-
# - for j in $(ls -d */); do for i in $(find $j -type f -name "*.yara" ; find $j -type f -name "*.yar"); do echo $i; yara -x androguard=androguard_report.json $i testfile; if [[ $? -ne 0 ]]; then FALLO=1; fi; done; done
40-
- for i in $(ls *_index.yar); do echo $i; yara -w -x androguard=androguard_report.json $i testfile; if [[ $? -ne 0 ]]; then FALLO=1; fi; done
36+
- for i in $(ls *_index.yar); do echo $i; yara -w $i testfile; if [[ $? -ne 0 ]]; then FALLO=1; fi; done
4137
- exit $FALLO

Antidebug_AntiVM_index.yar

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Antidebug_AntiVM/antidebug_antivm.yar"
5+
include "./antidebug_antivm/antidebug_antivm.yar"

CVE_Rules_index.yar

+15-15
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,18 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./CVE_Rules/CVE-2010-0805.yar"
6-
include "./CVE_Rules/CVE-2010-0887.yar"
7-
include "./CVE_Rules/CVE-2010-1297.yar"
8-
include "./CVE_Rules/CVE-2012-0158.yar"
9-
include "./CVE_Rules/CVE-2013-0074.yar"
10-
include "./CVE_Rules/CVE-2013-0422.yar"
11-
include "./CVE_Rules/CVE-2015-1701.yar"
12-
include "./CVE_Rules/CVE-2015-2426.yar"
13-
include "./CVE_Rules/CVE-2015-2545.yar"
14-
include "./CVE_Rules/CVE-2015-5119.yar"
15-
include "./CVE_Rules/CVE-2016-5195.yar"
16-
include "./CVE_Rules/CVE-2017-11882.yar"
17-
include "./CVE_Rules/CVE-2018-20250.yar"
18-
include "./CVE_Rules/CVE-2018-4878.yar"
5+
include "./cve_rules/CVE-2010-0805.yar"
6+
include "./cve_rules/CVE-2010-0887.yar"
7+
include "./cve_rules/CVE-2010-1297.yar"
8+
include "./cve_rules/CVE-2012-0158.yar"
9+
include "./cve_rules/CVE-2013-0074.yar"
10+
include "./cve_rules/CVE-2013-0422.yar"
11+
include "./cve_rules/CVE-2015-1701.yar"
12+
include "./cve_rules/CVE-2015-2426.yar"
13+
include "./cve_rules/CVE-2015-2545.yar"
14+
include "./cve_rules/CVE-2015-5119.yar"
15+
include "./cve_rules/CVE-2016-5195.yar"
16+
include "./cve_rules/CVE-2017-11882.yar"
17+
include "./cve_rules/CVE-2018-20250.yar"
18+
include "./cve_rules/CVE-2018-4878.yar"

Capabilities_index.yar

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Capabilities/capabilities.yar"
5+
include "./capabilities/capabilities.yar"

Crypto_index.yar

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Crypto/crypto_signatures.yar"
5+
include "./crypto/crypto_signatures.yar"

Exploit-Kits_index.yar

-15
This file was deleted.

Malicious_Documents_index.yar

-23
This file was deleted.

Mobile_Malware_index.yar

+1-64
Original file line numberDiff line numberDiff line change
@@ -1,67 +1,4 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Mobile_Malware/Android_ASSDdeveloper.yar"
6-
include "./Mobile_Malware/Android_AVITOMMS.yar"
7-
include "./Mobile_Malware/Android_AliPay_smsStealer.yar"
8-
include "./Mobile_Malware/Android_Amtrckr_20160519.yar"
9-
include "./Mobile_Malware/Android_Backdoor.yar"
10-
include "./Mobile_Malware/Android_Backdoor_script.yar"
11-
include "./Mobile_Malware/Android_BadMirror.yar"
12-
include "./Mobile_Malware/Android_Banker_Acecard.yar"
13-
include "./Mobile_Malware/Android_BatteryBot_ClickFraud.yar"
14-
include "./Mobile_Malware/Android_Clicker_G.yar"
15-
include "./Mobile_Malware/Android_Copy9.yar"
16-
include "./Mobile_Malware/Android_DeathRing.yar"
17-
include "./Mobile_Malware/Android_Dectus_rswm.yar"
18-
include "./Mobile_Malware/Android_Dendroid_RAT.yar"
19-
include "./Mobile_Malware/Android_Dogspectus.yar"
20-
include "./Mobile_Malware/Android_FakeApps.yar"
21-
include "./Mobile_Malware/Android_FakeBank_Fanta.yar"
22-
include "./Mobile_Malware/Android_Godless.yar"
23-
include "./Mobile_Malware/Android_HackintTeam_Implant.yar"
24-
include "./Mobile_Malware/Android_Libyan_Scorpions.yar"
25-
include "./Mobile_Malware/Android_MalwareCertificates.yar"
26-
include "./Mobile_Malware/Android_Malware_Ramsonware.yar"
27-
include "./Mobile_Malware/Android_Malware_Tinhvan.yar"
28-
include "./Mobile_Malware/Android_Malware_Towelroot.yar"
29-
include "./Mobile_Malware/Android_Marcher_2.yar"
30-
include "./Mobile_Malware/Android_MazarBot_z.yar"
31-
include "./Mobile_Malware/Android_Metasploit.yar"
32-
include "./Mobile_Malware/Android_Metasploit_Payload.yar"
33-
include "./Mobile_Malware/Android_OmniRat.yar"
34-
include "./Mobile_Malware/Android_Overlayer.yar"
35-
include "./Mobile_Malware/Android_Pink_Locker.yar"
36-
include "./Mobile_Malware/Android_Polish_Bankbot.yar"
37-
include "./Mobile_Malware/Android_RuMMS.yar"
38-
include "./Mobile_Malware/Android_SMSFraud.yar"
39-
include "./Mobile_Malware/Android_SandroRat.yar"
40-
include "./Mobile_Malware/Android_SlemBunk.yar"
41-
include "./Mobile_Malware/Android_SpyAgent.yar"
42-
include "./Mobile_Malware/Android_SpyNote.yar"
43-
include "./Mobile_Malware/Android_Spynet.yar"
44-
include "./Mobile_Malware/Android_Spywaller.yar"
45-
include "./Mobile_Malware/Android_Switcher.yar"
46-
include "./Mobile_Malware/Android_Tachi.yar"
47-
include "./Mobile_Malware/Android_Tempting_Cedar_Spyware.yar"
48-
include "./Mobile_Malware/Android_Tordow.yar"
49-
include "./Mobile_Malware/Android_Triada_Banking.yar"
50-
include "./Mobile_Malware/Android_Trojan_Dendroid.yar"
51-
include "./Mobile_Malware/Android_Trojan_Droidjack.yar"
52-
include "./Mobile_Malware/Android_VikingOrder.yar"
53-
include "./Mobile_Malware/Android_VirusPolicia.yar"
54-
include "./Mobile_Malware/Android_adware.yar"
55-
include "./Mobile_Malware/Android_generic_adware.yar"
56-
include "./Mobile_Malware/Android_generic_smsfraud.yar"
57-
include "./Mobile_Malware/Android_malware_Advertising.yar"
58-
include "./Mobile_Malware/Android_malware_ChinesePorn.yar"
59-
include "./Mobile_Malware/Android_malware_Dropper.yar"
60-
include "./Mobile_Malware/Android_malware_Fake_MosKow.yar"
61-
include "./Mobile_Malware/Android_malware_HackingTeam.yar"
62-
include "./Mobile_Malware/Android_malware_SMSsender.yar"
63-
include "./Mobile_Malware/Android_malware_banker.yar"
64-
include "./Mobile_Malware/Android_malware_xbot007.yar"
65-
include "./Mobile_Malware/Android_mapin.yar"
66-
include "./Mobile_Malware/Android_pornClicker.yar"
67-
include "./Mobile_Malware/Android_sk_bankTr.yar"

Packers_index.yar

+6-6
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Packers/JJencode.yar"
6-
include "./Packers/Javascript_exploit_and_obfuscation.yar"
7-
include "./Packers/packer.yar"
8-
include "./Packers/packer_compiler_signatures.yar"
9-
include "./Packers/peid.yar"
5+
include "./packers/JJencode.yar"
6+
include "./packers/Javascript_exploit_and_obfuscation.yar"
7+
include "./packers/packer.yar"
8+
include "./packers/packer_compiler_signatures.yar"
9+
include "./packers/peid.yar"

README.md

+6-7

Webshells_index.yar

+9-9
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
5-
include "./Webshells/WShell_APT_Laudanum.yar"
6-
include "./Webshells/WShell_ASPXSpy.yar"
7-
include "./Webshells/WShell_PHP_Anuna.yar"
8-
include "./Webshells/WShell_PHP_in_images.yar"
9-
include "./Webshells/WShell_THOR_Webshells.yar"
10-
include "./Webshells/Wshell_ChineseSpam.yar"
11-
include "./Webshells/Wshell_fire2013.yar"
12-
include "./Webshells/WShell_Drupalgeddon2_icos.yar"
5+
include "./webshells/WShell_APT_Laudanum.yar"
6+
include "./webshells/WShell_ASPXSpy.yar"
7+
include "./webshells/WShell_Drupalgeddon2_icos.yar"
8+
include "./webshells/WShell_PHP_Anuna.yar"
9+
include "./webshells/WShell_PHP_in_images.yar"
10+
include "./webshells/WShell_THOR_Webshells.yar"
11+
include "./webshells/Wshell_ChineseSpam.yar"
12+
include "./webshells/Wshell_fire2013.yar"
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.

email_index.yar

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
/*
22
Generated by Yara-Rules
3-
On 26-11-2019
3+
On 08-01-2020
44
*/
55
include "./email/EMAIL_Cryptowall.yar"
66
include "./email/attachment.yar"
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.

exploit_kits_index.yar

+15
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
/*
2+
Generated by Yara-Rules
3+
On 08-01-2020
4+
*/
5+
include "./exploit_kits/EK_Angler.yar"
6+
include "./exploit_kits/EK_Blackhole.yar"
7+
include "./exploit_kits/EK_BleedingLife.yar"
8+
include "./exploit_kits/EK_Crimepack.yar"
9+
include "./exploit_kits/EK_Eleonore.yar"
10+
include "./exploit_kits/EK_Fragus.yar"
11+
include "./exploit_kits/EK_Phoenix.yar"
12+
include "./exploit_kits/EK_Sakura.yar"
13+
include "./exploit_kits/EK_ZeroAcces.yar"
14+
include "./exploit_kits/EK_Zerox88.yar"
15+
include "./exploit_kits/EK_Zeus.yar"

0 commit comments

Comments
 (0)