-
Notifications
You must be signed in to change notification settings - Fork 55
/
HiddenVNC.yar
29 lines (26 loc) · 879 Bytes
/
HiddenVNC.yar
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
import "pe"
rule HiddenVNC
{
meta:
id = "15zXm5IVJkjh5ERo8y3PsR"
fingerprint = "4910c9889e5940a74cb40eab4738c519c045a4ffa48fbb69c175e65421e86563"
version = "1.0"
creation_date = "2020-01-01"
first_imported = "2021-12-30"
last_modified = "2021-12-30"
status = "RELEASED"
sharing = "TLP:WHITE"
source = "BARTBLAZE"
author = "@bartblaze"
description = "Identifies HiddenVNC, which can start remote sessions."
category = "MALWARE"
mitre_att = "T1021.005"
strings:
$ = "#hvnc" ascii wide
$ = "VNC is starting your browser..." ascii wide
$ = "HvncAction" ascii wide
$ = "HvncCommunication" ascii wide
$ = "hvncDesktop" ascii wide
condition:
2 of them or (pe.exports("VncStartServer") and pe.exports("VncStopServer"))
}