## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-DEADBITS-YARA-RULES

# yara-rules
مجموعة من توقيعات YARA من أبحاث البرمجيات الخبيثة الحديثة
## مجموعة القواعد
**حصان طروادة Dacls**
* القاعدة: Dacls_Linux.yara
* القاعدة: Dacls_Windows.yara
* المرجع: https://blog.netlab.360.com/dacls-the-dual-platform-rat/
**APT32 KerrDown**
* القاعدة: APT32_KerrDown.yara
* المرجع: https://unit42.paloaltonetworks.com/tracking-oceanlotus-new-downloader-kerrdown/
* * *
**ACBackdoor - إصدار Linux**
* القاعدة: ACBackdoor_Linux.rule
* المرجع: Intezer
* * *
**برمجية فدية غير مسمّاة لأنظمة Linux مكتوبة بلغة Golang**
* القاعدة: Linux_Golang_Ransomware.rule
* المرجع: مدونة Fortinet
* * *
**KPOT v2**
* القاعدة: KPOT_v2.yara
* المرجع: (ProofPoint Threat Insight)[https://www.proofpoint.com/us/threat-insight/post/new-kpot-v20-stealer-brings-zero-persistence-and-memory-features-silently-steal]
* * *
**بوت نت WatchBog لأنظمة Linux**
* القاعدة: WatchBog_Linux.yara
* المراجع:
* https://twitter.com/polarply/status/1153232987762376704
* https://www.alibabacloud.com/blog/return-of-watchbog-exploiting-jenkins-cve-2018-1000861_594798
* * *
**برمجية EvilGnome الخبيثة لأنظمة Linux**
* القاعدة: EvilGnome_Linux.yara
* المرجع: Intezer
* * *
**APT34 PICKPOCKET**
* القاعدة: APT34_PICKPOCKET.yara
* المرجع: FireEye Threat Reseearch
* * *
**APT34 LONGWATCH**
* القاعدة: APT34_LONGWATCH.yara
* المرجع: FireEye Threat Reseearch
* * *
**APT34 VALUEVAULT**
* القاعدة: APT34_VALUEVAULT.yara
* المرجع: FireEye Threat Reseearch
* * *
**أداة RedGhost لأنظمة Linux**
* القاعدة: RedGhost_Linux
* المرجع: مستودع RedGhost على GitHub
* * *
**SilentTrinity**
* القاعدة: SilentTrinity_Payload.rule
* القاعدة: SilentTrinity_Delivery.rule
* المرجع: Countercept
* * *
**DNSpionage**
* القاعدة: DNSpionage.yara
* المراجع: Talos Intelligence, Talos Intelligence #2
* * *
**TA505 FlowerPippi**
* القاعدة: TA505_FlowerPippi.yara
* المرجع: https://blog.trendmicro.com/trendlabs-security-intelligence/latest-spam-campaigns-from-ta505-now-using-new-malware-tools-gelup-and-flowerpippi/
* * *
**REMCOS RAT**
* القاعدة: REMCOS_RAT_2019.yara
* المرجع: https://exchange.xforce.ibmcloud.com/collection/Remcos-Rat-Delivered-via-Email-Campaign-056f98e4fc97bd142337d6b2271aeaa7
* * *
**الباب الخلفي GodLua لأنظمة Linux**
* القاعدة: godlua_linux.yara
* المرجع: https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/
* * *
**APT32 Ratsnif**
* القاعدة: apt32-ratsnif.yara
* المرجع: https://threatvector.cylance.com/en_us/home/threat-spotlight-ratsnif-new-network-vermin-from-oceanlotus.html
* * *
**OSX/CrescentCore**
* القاعدة: crescentcore_dmg.yara
* المرجع: https://www.intego.com/mac-security-blog/osx-crescentcore-mac-malware-designed-to-evade-antivirus/
ملاحظة جانبية: _متى سنقرر جميعًا تغيير أسماء توقيعات mac إلى macOS/ ؟ فقد فات أوان ذلك منذ زمن بعيد، في رأيي المتواضع_
* * *
**WarZone RAT المعروف أيضًا باسم Ave Maria Stealer**
* القاعدة: avemaria_warzone.yara
* المرجع: http://blog.morphisec.com/threat-alert-ave-maria-infostealer-on-the-rise-with-new-stealthier-delivery
* * *
**Winnti Linux**
* القاعدة: winnti_linux.yara
* المرجع: https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a