Files
nuclei-templates/file/malware/pythorat-malware.yaml
2024-12-01 13:57:55 +00:00

25 lines
721 B
YAML

id: pythorat-malware
info:
name: PythoRAT Malware - Detect
author: daffainfo
severity: info
reference: https://github.com/Yara-Rules/rules/blob/master/malware/RAT_Ratdecoders.yar
tags: malware,file
file:
- extensions:
- all
matchers:
- type: word
part: raw
words:
- "TKeylogger"
- "uFileTransfer"
- "TTDownload"
- "SETTINGS"
- "Unknown"
- "#@#@#"
- "PluginData"
- "OnPluginMessage"
condition: and
# digest: 490a004630440220429443948ef7797c1019426118a3c534d8526972f6c542fb648722280167912802203e554fe54cc616cb26e8fda5cdbf403f7b693616a5cf13e62ae3e8bc3d795ccb:922c64590222798bb761d5b6d8e72950