Skip to content

Commit

Permalink
Update third-party rules as of 2024-12-24 (#737)
Browse files Browse the repository at this point in the history
Co-authored-by: Update third-party rules <41898282+github-actions[bot]@users.noreply.github.com>
  • Loading branch information
octo-sts[bot] and github-actions[bot] authored Dec 24, 2024
1 parent f658e86 commit 0dbd3ac
Show file tree
Hide file tree
Showing 15 changed files with 42,746 additions and 18,996 deletions.
1 change: 1 addition & 0 deletions tests/linux/2021.XMR-Stak/1b1a56.elf.simple
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# linux/2021.XMR-Stak/1b1a56.elf: critical
3P/TTC-CERT/kittipongk_cryptominer_xmr: high
3P/elastic/cryptominer_stak: critical
3P/sekoia/miner_lin_xmrig: critical
c2/addr/http_dynamic: medium
c2/addr/ip: medium
c2/addr/url: low
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2022.bpfdoor/bpfdoor_1.simple
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# linux/2022.bpfdoor/bpfdoor_1: critical
3P/elastic/bpfdoor: critical
3P/sekoia/backdoor_lin_bpfdoor: critical
3P/sig_base/redmenshen_bpfdoor: critical
data/random/insecure: low
exec/program: medium
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.Gelsemium/dbus.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.Gelsemium/dbus: critical
3P/sekoia/gelsemium_firewood_backdoor: critical
anti-static/elf/multiple: medium
crypto/decrypt: low
crypto/encrypt: medium
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.Gelsemium/kde.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.Gelsemium/kde: critical
3P/sekoia/gelsemium_wolfsbane_launcher: critical
crypto/rc4: low
discover/process/name: medium
evasion/file/location/dev_shm: high
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.Gelsemium/libselinux.so.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.Gelsemium/libselinux.so: critical
3P/sekoia/gelsemium_wolfsbane_rootkit: critical
anti-static/obfuscation/hidden_literals: medium
anti-static/xor/commands: high
anti-static/xor/paths: high
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.Gelsemium/udevd.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.Gelsemium/udevd: critical
3P/sekoia/gelsemium_wolfsbane_backdoor: critical
anti-static/elf/multiple: medium
c2/addr/ip: medium
c2/addr/url: low
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.Gelsemium/udevd_multi.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.Gelsemium/udevd_multi: critical
3P/sekoia/gelsemium_wolfsbane_backdoor: critical
anti-static/elf/multiple: medium
c2/addr/ip: medium
c2/addr/url: low
Expand Down
1 change: 1 addition & 0 deletions tests/linux/2024.chisel/crondx.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2024.chisel/crondx: critical
3P/sekoia/chisel_strings: critical
c2/addr/ip: high
c2/addr/url: low
c2/tool_transfer/arch: low
Expand Down
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_decrease.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_increase.mdiff
Binary file not shown.
3 changes: 3 additions & 0 deletions tests/macOS/2023.3CX/libffmpeg.dirty.dylib.simple
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
# macOS/2023.3CX/libffmpeg.dirty.dylib: critical
3P/sekoia/downloader_smooth_operator: critical
3P/sig_base/3cxdesktopapp_backdoor: critical
3P/sig_base/nk_3cx_dylib: critical
3P/sig_base/susp_xored_mozilla: critical
3P/volexity/iconic: critical
anti-static/xor/user_agent: critical
c2/addr/url: low
c2/tool_transfer/arch: low
Expand Down
Binary file modified tests/macOS/2023.3CX/libffmpeg.dirty.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.increase.mdiff
Binary file not shown.
2 changes: 1 addition & 1 deletion third_party/yara/YARAForge/RELEASE
Original file line number Diff line number Diff line change
@@ -1 +1 @@
20241222
20241223
61,729 changes: 42,734 additions & 18,995 deletions third_party/yara/YARAForge/yara-rules-full.yar

Large diffs are not rendered by default.

0 comments on commit 0dbd3ac

Please sign in to comment.