Skip to content

Commit 46daf42

Browse files
authored
Merge pull request #342 from JPMinty/octowave_loader_addition
Create mal_octwave_loader_sup_file_mar25.yar
2 parents abdc799 + a37eac3 commit 46daf42

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed
+24
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
rule Octowave_Loader_Supporting_File_03_2025
2+
{
3+
meta:
4+
description = "Detects supporting file used by Octowave Loader containing hardcoded values"
5+
author = "Jai Minton (@CyberRaiju) - HuntressLabs"
6+
date = "2025-03-19"
7+
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
8+
yt_reference = "https://www.youtube.com/watch?v=NiNIbkiuExU"
9+
reference = "https://x.com/CyberRaiju/status/1893450184224362946?t=u0X6ST2Qgnrf-ujjphGOSg&s=19"
10+
hash1 = "C4CBAA7E4521FA0ED9CC634C5E2BACBF41F46842CA4526B7904D98843A7E9DB9"
11+
hash2 = "F5CFB2E634539D5DC7FFE202FFDC422EF7457100401BA1FBC21DD05558719865"
12+
hash3 = "56F1967F7177C166386D864807CDF03D5BBD3F118A285CE67EA226D02E5CF58C"
13+
hash4 = "11EE5AD8A81AE85E5B7DDF93ADF6EDD20DE8460C755BF0426DFCBC7F658D7E85"
14+
hash5 = "D218B65493E4D9D85CBC2F7B608F4F7E501708014BC04AF27D33D995AA54A703"
15+
hash6 = "0C112F9DFE27211B357C74F358D9C144EA10CC0D92D6420B8742B72A65562C5A"
16+
strings:
17+
$unique_key = {1D 1C 1F 1E 01 01 03 02 05 04 07 06 09 D4 0E 0A 0D 0C 0F 0E 31 30 31 32 35 34 36 36 39 38 DC 3F 3D 3C 3E} // 1012546698 unknown unique identifier and surrounding bytes
18+
$unique_string = "MLONqpsrutwvyx"
19+
$unique_string2 = "A@CBEDGFIHKJMLONqpsrutwvyx"
20+
condition:
21+
(uint16(0) != 0x5a4d)
22+
and filesize < 10000KB
23+
and all of them
24+
}

0 commit comments

Comments
 (0)