HK0X(@Harshitkoli13) 's Twitter Profile Photo


Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.

github.com/hk0x1/Yara-Rul…

#100DaysOfYARA 
Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.

github.com/hk0x1/Yara-Rul…
account_circle
Natalie Zargarov(@NZargarov) 's Twitter Profile Photo


BruteRatel detection based on anti-debugging and anti-hooking techniques along with some NT function hashes.

github.com/rapid7/Rapid7-…

#100DaysOfYara #R7_Labs
BruteRatel detection based on anti-debugging and anti-hooking techniques along with some NT function hashes.

github.com/rapid7/Rapid7-…
account_circle
Jonathan Peters(@cod3nym) 's Twitter Profile Photo

Day 14:
Another rule for a technique. This rule targets the Right-To-Left (RLO) extension spoofing technique.This spoofing also works on VT but only in the GUI, the URL shows the actual file %E2%80%AEfdp.exe

E2 80 AE are the bytes encoding the…

#100DaysOfYara Day 14:
Another rule for a #UnprotectProject technique. This rule targets the Right-To-Left (RLO) extension spoofing technique.This spoofing also works on VT but only in the GUI, the URL shows the actual file %E2%80%AEfdp.exe 

E2 80 AE are the bytes encoding the…
account_circle
Yashraj Solanki(@RustyNoob619) 's Twitter Profile Photo

All of my rules from the 100DaysofYARA challenge are copied over to my new YARA GitHub repo and also renamed the rule files for easier identification 🐧

Link to Repo: github.com/RustyNoob-619/…

I plan to keep adding to this repo and building it up over the year 💪

All of my #YARA rules from the 100DaysofYARA challenge are copied over to my new YARA GitHub repo and also renamed the rule files for easier identification 🐧

Link to Repo: github.com/RustyNoob-619/… 

I plan to keep adding to this repo and building it up over the year 💪
account_circle
Yashraj Solanki(@RustyNoob619) 's Twitter Profile Photo



Final post on the challenge for this year, just wanted to share the awesome swag that I received today courtesy of Greg Lesnewich

It was an absolute pleasure participating along side others 🐧

Catch you all next year, until then, stay frosty...

#100DaysofYARA 

Final post on the challenge for this year, just wanted to share the awesome swag that I received today courtesy of @greglesnewich  

It was an absolute pleasure participating along side others 🐧

Catch you all next year, until then, stay frosty...
account_circle
ANY.RUN(@anyrun_app) 's Twitter Profile Photo

🎯 Hunt unique samples

💫 Would you like to develop threat hunting rules?

📌 Here is an example of how you can do it for the unknown samples of AdWind ( ), a Java-based with remote access capabilities.

✍️ Just follow these steps:

1⃣…

🎯 Hunt unique #AdWind samples #100DaysofYARA

💫 Would you like to develop threat hunting #YARA rules?

📌 Here is an example of how you can do it for the unknown samples of AdWind (#AlienSpy), a Java-based #MaaS with remote access capabilities.

✍️ Just follow these steps:

1⃣…
account_circle
Jonathan Peters(@cod3nym) 's Twitter Profile Photo

Day 16:
Today I wrote a rule for the PyArmor python obfuscator. A simple rule checking for common strings used by the obfuscators runtime. Also contributing this to

github.com/cod3nym/detect…

#100DaysOfYara Day 16: 
Today I wrote a rule for the PyArmor python obfuscator. A simple rule checking for common strings used by the obfuscators runtime. Also contributing this to #UnprotectProject

github.com/cod3nym/detect…
account_circle
Maik Morgenstern(@TriggerMeHappy) 's Twitter Profile Photo

We at AV-TEST GmbH test IT security. So I wanted to join and see how well YARA rules perform compared to the EPP products we test regularly. I used the different rule sets from the YARA Forge project provided by Florian Roth

Read the thread for all details!

We at @avtestorg test IT security. So I wanted to join #100DaysOfYARA and see how well YARA rules perform compared to the EPP products we test regularly. I used the different rule sets from the YARA Forge project provided by @cyb3rops

Read the thread for all details!
account_circle
Thomas Roccia 🤘(@fr0gger_) 's Twitter Profile Photo

I stopped the 🙈 because I got swamped with other work & life but during my stint with the challenge, I released YaraToolkit and DocYara (which, let's just say, took me quite some time to create). 🤓

🛠️YaraToolkit is your all-in-one Yara go-to spot 🌟—from…

I stopped the #100daysofYara 🙈 because I got swamped with other work & life but during my stint with the challenge, I released YaraToolkit and DocYara (which, let's just say, took me quite some time to create). 🤓 

🛠️YaraToolkit is your all-in-one Yara go-to spot 🌟—from…
account_circle
Yashraj Solanki(@RustyNoob619) 's Twitter Profile Photo



I think this challenge was a huge success...

Kudos to Greg Lesnewich for creating such an awesome initiative, Thomas Roccia 🤘 for building YARA toolkit which was super handy, Steve YARA Synapse Miller for the motivation 🐧

I also wrote a Blog on it ⬇️

rustynoob-619.github.io/100-Days-of-YA…

#100DaysofYARA

I think this challenge was a huge success...

Kudos to @greglesnewich for creating such an awesome initiative, @fr0gger_ for building YARA toolkit which was super handy, @stvemillertime for the motivation 🐧

I also wrote a Blog on it ⬇️

rustynoob-619.github.io/100-Days-of-YA…
account_circle
Andrew Northern 𓅓(@ex_raritas) 's Twitter Profile Photo

Captains log - Day 11 of I stumbled upon a fork of Mirai called Hailbot that seems to be targeting Huawei hardware in hopes of building a botnet with aim of providing a Denial of Service as ...a Service(???lol).

How am I so sure its Hailbot? well first the YARA…

Captains log - Day 11 of #100DaysOfYara I stumbled upon a fork of Mirai called Hailbot that seems to be targeting Huawei hardware in hopes of building a botnet with aim of providing a Denial of Service as ...a Service(???lol).

How am I so sure its Hailbot?  well first the YARA…
account_circle
Matthew Green 🌻(@mgreen27) 's Twitter Profile Photo

I use a similar technique to this querying logs remotely as the rule can then return the whole line for context instead of just the string hit.
Here is a an example looking for a line hit adding in anchors at beginning and end targeting access logs.
Pretty much…

#100daysofYARA I use a similar technique  to this querying logs remotely as the rule can then return the whole line for context instead of just the string hit.
Here is a an  example looking for a line hit adding in anchors at beginning and end targeting access logs. 
Pretty much…
account_circle
alden(@birchb0y) 's Twitter Profile Photo

wrote a lil helper binja script to clean up the __cstring section of a macho file!

its not always perfect but it generally makes the rev experience nicer (esp for those grinding 🫡)

gist.github.com/ald3ns/bc3bcc6…

wrote a lil helper binja script to clean up the __cstring section of a macho file! 

its not always perfect but it generally makes the rev experience nicer (esp for those grinding #100DaysOfYara 🫡)

gist.github.com/ald3ns/bc3bcc6…
account_circle