Skip to content

Commit

Permalink
Fixed FP for Emotet yara rule #17
Browse files Browse the repository at this point in the history
  • Loading branch information
shu-tom committed Aug 16, 2021
1 parent 3741319 commit ccb8a64
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 6 deletions.
5 changes: 2 additions & 3 deletions utils/emotetscan.py
Original file line number Diff line number Diff line change
Expand Up @@ -36,12 +36,11 @@
strings: \
$v4a = { BB 00 C3 4C 84 } \
$v4b = { B8 00 C3 CC 84 } \
$v5a = { 69 01 6D 4E C6 41 05 39 30 00 00} \
$v5b = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 } \
$v5a = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 } \
$v6a = { C7 40 20 ?? ?? ?? 00 C7 40 10 ?? ?? ?? 00 C7 40 0C 00 00 00 00 83 3C CD ?? ?? ?? ?? 00 74 0E 41 89 48 ?? 83 3C CD ?? ?? ?? ?? 00 75 F2 } \
$v7a = { 6A 06 33 D2 ?? F7 ?? 8B DA 43 74 } \
$v7b = { 83 E6 0F 8B CF 83 C6 04 50 8B D6 E8 ?? ?? ?? ?? 59 6A 2F 8D 3C 77 58 66 89 07 83 C7 02 4B 75 } \
condition: all of ($v4*) or $v5a or $v5b or $v6a or all of ($v7*)}'
condition: all of ($v4*) or $v5a or $v6a or all of ($v7*)}'
}

# MZ Header
Expand Down
5 changes: 2 additions & 3 deletions yara/rule.yara
Original file line number Diff line number Diff line change
Expand Up @@ -167,13 +167,12 @@ rule Emotet {
strings:
$v4a = { BB 00 C3 4C 84 }
$v4b = { B8 00 C3 CC 84 }
$v5a = { 69 01 6D 4E C6 41 05 39 30 00 00 }
$v5b = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 }
$v5a = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 }
$v6a = { C7 40 20 ?? ?? ?? 00 C7 40 10 ?? ?? ?? 00 C7 40 0C 00 00 00 00 83 3C CD ?? ?? ?? ?? 00 74 0E 41 89 48 ?? 83 3C CD ?? ?? ?? ?? 00 75 F2 }
$v7a = { 6A 06 33 D2 ?? F7 ?? 8B DA 43 74 }
$v7b = { 83 E6 0F 8B CF 83 C6 04 50 8B D6 E8 ?? ?? ?? ?? 59 6A 2F 8D 3C 77 58 66 89 07 83 C7 02 4B 75 }
condition: all of ($v4*) or $v5a or $v5b or $v6a or all of ($v7*)
condition: all of ($v4*) or $v5a or $v6a or all of ($v7*)
}

rule SmokeLoader {
Expand Down

0 comments on commit ccb8a64

Please sign in to comment.