Google Chronicle unknown experimental yara-l

malware_bankshot

Bankshot malware

View Source

Detection Logic

/*
 * Copyright 2021 Google LLC
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     https://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES 
OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

rule malware_bankshot
{
  meta:
    author = "Google Cloud Security"
    description = "Bankshot malware"
    reference = "https://attack.mitre.org/software/S0239/"
    yara_version = "YL2.0"
    rule_version = "1.0"

  events:
    (
      (
        $e1.metadata.event_type = "REGISTRY_MODIFICATION" or
        $e1.metadata.event_type = "REGISTRY_CREATION"
      )
      and
      re.regex($e1.target.registry.registry_key, `(HKLM
| HKEY_LOCAL_MACHINE)\\SOFTWARE\\Microsoft\\Pniumj`) nocase
    )
    or
    (
      $e1.network.direction = "INBOUND" and
      $e1.target.port = 1058 and
      $e1.network.sent_bytes > 10000
    )

  condition:
    $e1
}

Field Validations

Loading…

Comments (0)

Loading comments...