Skip to content

Commit

Permalink
Update third-party rules as of 2024-12-16 (#706)
Browse files Browse the repository at this point in the history
Co-authored-by: Update third-party rules <41898282+github-actions[bot]@users.noreply.github.com>
  • Loading branch information
octo-sts[bot] and github-actions[bot] authored Dec 16, 2024
1 parent ed8a34c commit 9be53ee
Show file tree
Hide file tree
Showing 9 changed files with 41,103 additions and 45,127 deletions.
1 change: 1 addition & 0 deletions tests/linux/2021.FontOnLake/45E9.elf.simple
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# linux/2021.FontOnLake/45E9.elf: critical
3P/elastic/rootkit: high
3P/elastic/rootkit_fontonlake: critical
anti-static/packer/upx: high
c2/addr/ip: high
Expand Down
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_decrease.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.change_increase.mdiff
Binary file not shown.
2 changes: 0 additions & 2 deletions tests/macOS/2023.3CX/libffmpeg.dirty.dylib.simple
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
# macOS/2023.3CX/libffmpeg.dirty.dylib: critical
3P/sig_base/3cxdesktopapp_backdoor: critical
3P/sig_base/nk_3cx_dylib: critical
3P/sig_base/susp_xored_mozilla: critical
3P/volexity/iconic: critical
anti-static/xor/user_agent: critical
c2/addr/url: low
c2/tool_transfer/arch: low
Expand Down
Binary file modified tests/macOS/2023.3CX/libffmpeg.dirty.mdiff
Binary file not shown.
Binary file modified tests/macOS/2023.3CX/libffmpeg.increase.mdiff
Binary file not shown.
4 changes: 2 additions & 2 deletions tests/windows/2024.aspdasdksa2/callback.bat.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@
],
"RiskScore": 4,
"RiskLevel": "CRITICAL",
"RuleURL": "https://github.com/Neo23x0/signature-base/blob/b1bc331bada41a30f3b2f8943e750798f7aaa1a9/yara/gen_powershell_susp.yar#L52-L91",
"RuleURL": "https://github.com/Neo23x0/signature-base/blob/7f13b425aac90a00c208de8e3b28751b5aba3c45/yara/gen_powershell_susp.yar#L52-L91",
"ReferenceURL": "Internal%20Research",
"RuleAuthor": "Florian Roth (Nextron Systems)",
"RuleLicense": "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE",
"RuleLicenseURL": "https://github.com/Neo23x0/signature-base/blob/b1bc331bada41a30f3b2f8943e750798f7aaa1a9/LICENSE",
"RuleLicenseURL": "https://github.com/Neo23x0/signature-base/blob/7f13b425aac90a00c208de8e3b28751b5aba3c45/LICENSE",
"ID": "3P/sig_base/powershell_webdownload",
"RuleName": "SIGNATURE_BASE_Suspicious_Powershell_Webdownload_1"
},
Expand Down
2 changes: 1 addition & 1 deletion third_party/yara/YARAForge/RELEASE
Original file line number Diff line number Diff line change
@@ -1 +1 @@
20241208
20241215
86,221 changes: 41,099 additions & 45,122 deletions third_party/yara/YARAForge/yara-rules-full.yar

Large diffs are not rendered by default.

0 comments on commit 9be53ee

Please sign in to comment.