Skip to content

Commit

Permalink
Arxan rule more tailored
Browse files Browse the repository at this point in the history
  • Loading branch information
enovella committed Oct 15, 2017
1 parent 37c245a commit 400467d
Showing 1 changed file with 15 additions and 3 deletions.
18 changes: 15 additions & 3 deletions apkid/rules/dex/obfuscators.yara
Expand Up @@ -113,12 +113,24 @@ rule bitwise_antiskid : obfuscator
rule arxan : obfuscator
{
meta:
description = "Arxan"
description = "Arxan Dalvik"

strings:
$obf_package = "Lxxxxxx/"
$obf_package1 = "Lxxxxxx/"
$obf_package2 = "Ltttttt/"
$russian_char1 = "ййй"
$russian_char2 = "ЧЧЧ"
$russian_char3 = "ЯЯЯ"
$russian_char4 = "жжж"
$russian_char5 = "ЧЧ"
$russian_char6 = "лл"
$russian_char7 = "ии"
$russian_char8 = "ПП"
$russian_char9 = "УУ"
condition:
is_dex and
$obf_package
($obf_package1 or $obf_package2) and
($russian_char1 or $russian_char2 or $russian_char3 or $russian_char4) and
($russian_char5 and $russian_char6 and $russian_char7 and $russian_char8 and $russian_char9)
}

0 comments on commit 400467d

Please sign in to comment.