-
Notifications
You must be signed in to change notification settings - Fork 171
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add PlugX rule proposed in #469 #515
Conversation
Signed-off-by: Still Hsu <[email protected]>
Signed-off-by: Still Hsu <[email protected]>
Per the linter, guess upstream needs to be updated to support the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks great to me, thanks!
only one suggestion to tweak the directory path for family rules. let's use "malware-family" instead of "malware". with that change, i'll be happy to merge.
Signed-off-by: Still Hsu <[email protected]>
Signed-off-by: Still Hsu <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
almost good to go, sorry for the annoyance with the little fixes
Signed-off-by: Still Hsu <[email protected]>
No problem. Hope the changes above are good now! |
- Some samples may attempt to scrub the timestamp by replacing it with an invalid date (e.g., 0x8888888) Signed-off-by: Still Hsu <[email protected]>
Signed-off-by: Still Hsu <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
final formatting issues (hopefully)
Co-authored-by: Moritz <[email protected]>
Co-authored-by: Moritz <[email protected]>
awesome, thank you very much! |
Summary
This PR adds the first malware-specific capa rule as initially proposed in issue #469. Specifically, this PR adds the known module watermarks found in various builds of PlugX.