[ << ALL_FEED ]

Yara-Yara

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

Yara-Yara–Yara!
🐧 Now that we’ve sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since generating them requires staring at raw assembler 😗

But sooner or later you’ll come across a sample that doesn’t contain the strings you need for detection 😶. Here are a couple of tips and examples 😌 on how to stop being afraid and start doing generate byte signatures on code:

🐾 There’s practically no point in writing a signature on a function’s prologue and epilogue: believe me, those push\pop are almost identical everywhere 😤

🐾 Try to latch onto constants or an unusual sequence of instructions: in backdoors, attackers often use custom packet encryption, which is very satisfying to detect

$code1 = {
    FF C6           // inc     esi
    B8 99 99 99 99  // mov     eax, 99999999h
    F7 EE           // imul    esi
    D1 FA           // sar     edx, 1
    8B C2           // mov     eax, edx
    C1 E8 1F        // shr     eax, 1Fh
    03 D0           // add     edx, eax
  }
Code language: Intel x86 Assembly (x86asm)


🐾 The compiler may change the order of instructions, or even insert alignment nops 😨. It wouldn’t hurt to use gaps between instructions — { <byte inst> [5-6] <byte inst2> }

🐾 All offsets (in jmp, call, etc.) should be replaced with ? signs, since offsets are changed by the compiler /*unless it’s handwritten shellcode*/ You can leave the upper 1-2 bytes of the offset in the signature — they’re almost always 00 or ff

$code61  = {
    68 DF 71 00 00  // push    71DFh           ; request
    53              // push    ebx             ; fd
    E8 ?? ?? ?? ??  // call    _ioctl 
  } // if the question marks are at the end of the byte construct, they can be removed entirely
Code language: Intel x86 Assembly (x86asm)


🐾 Keep in mind that the same opcode may operate on different registers from sample to sample 😫. To keep the signature relevant, you need to mask the operand bytes with ? signs in the instruction

$code21  = {
    89 ??                 // mov     edi, esi
    83 C? 01              // add     esi, 1
    83 E? 1F              // and     edi, 1Fh
    0F B6 ?? ?? 10        // movzx   edx, byte ptr [edx+eax+10h]
    83 C? 01              // add     eax, 1
    30 ?? ?? 28 03 00 00  // xor     [ebx+edi+328h], dl
    83 F? 0C              // cmp     eax, 0Ch
  }
Code language: Intel x86 Assembly (x86asm)


🐾 You can make a choice from several variants (<opcode1> | <opcode2>), when a series of samples uses different opcodes for a chain of instructions

  $code_3 = {
    80 34 (0? | 1? | 2? | 3?) 02  // xor byte ptr [eax + esi], 3
    4?                            // inc eax
    3D ?? ?? 00 00                // cmp eax, 0x21e6
    (7C | 72) ??                  // jl 0x10001322 \ jb ????????
    B? ?? ?? 00 00
  }
Code language: Intel x86 Assembly (x86asm)


All these assembler manipulations with byte signatures often have to be done with an opcode and instruction decoder. Fortunately, one of our colleagues created a plugin to help 😏 with signature generation, which replaces all parameterizable parts of a signature with ? and groups (x | y). The tool yarg works as a plugin for Ida Pro, generating a ready-made signature for a Yara rule for the selected code section. All you have to do is find a code section suitable for creating a signature 🙂

Good luck with your work!

#tips #malware #YARA
@ptescalator

More from global_author

More from global_author

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…