Yara-Yara
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
🐧 Now that we’ve sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since generating them requires staring at raw assembler 😗
But sooner or later you’ll come across a sample that doesn’t contain the strings you need for detection 😶. Here are a couple of tips and examples 😌 on how to
🐾 There’s practically no point in writing a signature on a function’s prologue and epilogue: believe me, those push\pop are almost identical everywhere 😤
🐾 Try to latch onto constants or an unusual sequence of instructions: in backdoors, attackers often use custom packet encryption, which is very satisfying to detect
$code1 = {
FF C6 // inc esi
B8 99 99 99 99 // mov eax, 99999999h
F7 EE // imul esi
D1 FA // sar edx, 1
8B C2 // mov eax, edx
C1 E8 1F // shr eax, 1Fh
03 D0 // add edx, eax
}
Code language: Intel x86 Assembly (x86asm)🐾 The compiler may change the order of instructions, or even insert alignment nops 😨. It wouldn’t hurt to use gaps between instructions —
{ <byte inst> [5-6] <byte inst2> } 🐾 All offsets (in jmp, call, etc.) should be replaced with
? signs, since offsets are changed by the compiler /*unless it’s handwritten shellcode*/ You can leave the upper 1-2 bytes of the offset in the signature — they’re almost always 00 or ff$code61 = {
68 DF 71 00 00 // push 71DFh ; request
53 // push ebx ; fd
E8 ?? ?? ?? ?? // call _ioctl
} // if the question marks are at the end of the byte construct, they can be removed entirely
Code language: Intel x86 Assembly (x86asm)🐾 Keep in mind that the same opcode may operate on different registers from sample to sample 😫. To keep the signature relevant, you need to mask the operand bytes with
? signs in the instruction$code21 = {
89 ?? // mov edi, esi
83 C? 01 // add esi, 1
83 E? 1F // and edi, 1Fh
0F B6 ?? ?? 10 // movzx edx, byte ptr [edx+eax+10h]
83 C? 01 // add eax, 1
30 ?? ?? 28 03 00 00 // xor [ebx+edi+328h], dl
83 F? 0C // cmp eax, 0Ch
}
Code language: Intel x86 Assembly (x86asm)🐾 You can make a choice from several variants
(<opcode1> | <opcode2>), when a series of samples uses different opcodes for a chain of instructions $code_3 = {
80 34 (0? | 1? | 2? | 3?) 02 // xor byte ptr [eax + esi], 3
4? // inc eax
3D ?? ?? 00 00 // cmp eax, 0x21e6
(7C | 72) ?? // jl 0x10001322 \ jb ????????
B? ?? ?? 00 00
}
Code language: Intel x86 Assembly (x86asm)All these assembler manipulations with byte signatures often have to be done with an opcode and instruction decoder. Fortunately, one of our colleagues created a plugin to help 😏 with signature generation, which replaces all parameterizable parts of a signature with
? and groups (x | y). The tool yarg works as a plugin for Ida Pro, generating a ready-made signature for a Yara rule for the selected code section. All you have to do is find a code section suitable for creating a signature 🙂Good luck with your work!
#tips #malware #YARA
@ptescalator
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…





