GNU/Linux ◆ xterm-256color ◆ bash 160 views

https://github.com/resteex0/yarex

Yarex

yarex is new face of uniq yara rule and is the YARA signature and IOC database for our scanners [resteex_scanner]

yarex is a project created to make the possibility of static malware analysis open and available to the public. yarex the objective to achivement the zero risk with conduct yarex in threat hunting or incident response or researching .

Getting Started

#requirements:

sudo apt-get install yara

option 1

sudo git clone https://github.com/resteex0/yarex.git --recursivesudo cd yarexsudo ls yarex/theZoo|awk '{print $9}'|while read A ; do yara yarex/theZoo/$A test3 2>&1;done

option 2 (recommended if researching or auditing)

sudo git clone https://github.com/resteex0/yarex.git --recursivecd yarexunzip -Pinfected testsample.zipcd ..sudo yarex/./resteex_scanner.sh yarex yarex/testsample

##Auditing and calibration

after option 2 as first should be have detect as some :

resteex_Win32_ZeroCleare yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_RedDelta yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_StrongPity yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_Unnamed_SpecMelt yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_FASTCash yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_All_ElectroRAT yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_SofacyCarberp yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_KerrDown yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_LuckyCat yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_FamousSparrow yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_MosesStaff yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Emotet yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Razy yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_REvil yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_AtomSilo yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Medusa_Locker yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Pysa yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Remcos yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Amavaldo yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Conti yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_YanluowangRansomware yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Cobalt_Strike yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Curator_Ransomware yarex/testsample/0468127a19daf4c7bc41015c5640fe1fresteex_Win32_ZeroCleare yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_RedDelta yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_StrongPity yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_Unnamed_SpecMelt yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_FASTCash yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_All_ElectroRAT yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_SofacyCarberp yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_KerrDown yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_LuckyCat yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Win32_FamousSparrow yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_MosesStaff yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Emotet yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Razy yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Babadeda yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_REvil yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_AtomSilo yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Medusa_Locker yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Pysa yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Remcos yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Amavaldo yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Conti yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_YanluowangRansomware yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Cobalt_Strike yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efcresteex_Curator_Ransomware yarex/testsample/0ceead2afcdee2a35dfa14e2054806231325dd291f9aa714af44a0495b677efc

License<br>

https://github.com/resteex0/yarex/blob/main/LICENSE