🧬
YARA Rules
File-based detection rules from YARAify/YARAhub — search, filter, and drill into CVE/malware-family/MITRE ATT&CK correlation per rule.
Tracked Rules
582
YARAify / YARAhub
With CVE Correlation
13
yara_rule_links
By Category
packer
10
stealer
5
loader
4
ransomware
3
By TLP
TLP:WHITE×578
TLP:AMBER×2
🧬 YARA Rule Browser582 results
YARAify · abuse.ch
🔍
582 rulesPage 1 / 12 · showing 1–50
| easyforme_infostealer | — | 🕵️ Stealer | — | TLP:WHITE | ✓ | 2025-05-29 |
| SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 Detects Naming Pattern used by ConfuserEx. ConfuserEx is a widely used open source obfuscator often found in malware | — | — | TLP:WHITE | ✓ | 2024-01-03 | |
| loader_win_bumblebee Find BumbleBee samples based on specific strings | win.bumblebee | — | TLP:WHITE | ✓ | 2022-06-02 | |
| SUS_Unsigned_APPX_MSIX_Installer_Feb23 Detects suspicious, unsigned Microsoft Windows APPX/MSIX Installer Packages | — | — | TLP:WHITE | ✓ | 2023-02-01 | |
| LNK_plugx_mustang_panda Detects LNK files with embedded obfuscated PowerShell scripts that extract and execute embedded payloads | — | — | TLP:WHITE | ✓ | 2026-01-12 | |
| HellsUchecker_Shellcode_Loader HellsUchecker x64 shellcode loader - position-independent code with SipHash-variant CTR cipher and aPLib decompression. Targets raw shellcode as injected via Hell's Gate NtCreateSection. | — | — | TLP:WHITE | ✓ | 2026-03-11 | |
| dependsonpythonailib Hunts for dependencies on Python AI libraries | — | — | TLP:WHITE | ✓ | 2025-05-10 | |
| win_valleyrat_stage1_heavy_loader Detects ValleyRAT Stage-1 Inflated Loader (Silver Fox) | — | — | TLP:WHITE | ✓ | 2026-08-08 | |
| shubstealer_stage2_applescript Detects SHubStealer stage-2 AppleScript payload by C2 endpoints and capability markers | — | — | TLP:WHITE | ✓ | 2026-04-17 | |
| MALDAC Detects samples designed to use WDAC to disable AV/EDR. False positives may occur. | — | — | TLP:WHITE | ✓ | 2025-11-18 | |
| globalnet_files Detect PE files compiled with PyInstaller with AntiDecompilation string. Observed in GlobalNet botnet campaign. | — | — | TLP:WHITE | ✓ | 2024-01-28 | |
| APT_Bitter_Maldoc_Verify Detects Bitter (T-APT-17) shellcode in oleObject (CVE-2018-0798) | — | 📄 Maldoc | 1 CVE | TLP:WHITE | ✓ | 2022-06-01 |
| EXE_ICS_IronGate_April2024 Detects Iron Gate ICS malware targeting simulation environment which appears to be a PoC | — | — | TLP:WHITE | ✓ | 2024-04-07 | |
| BadIIS_JKornevHidden attempts to match the strings found in BadIIS variant of the JKornevHidden rootkit | — | — | TLP:WHITE | ✓ | 2025-09-20 | |
| win_originbot Detects OriginBot(net) / OriginLoader malware. | — | — | TLP:WHITE | ✓ | 2024-01-04 | |
| TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments | — | 🛡️ Anti-Debug/VM | — | TLP:WHITE | ✓ | 2026-03-18 |
| DLL_RWX_S_Signed_Search Detects RWX-S signed DLLs. This verifies that the image contains a signature, not that it is valid. | — | — | TLP:WHITE | ✓ | 2024-09-19 | |
| MintsLoader_Victim_Profiler MintsLoader/TAG-124 victim profiler - sandbox detection and scoring | — | — | TLP:WHITE | ✓ | 2026-03-08 | |
| DLL_BankingTrojan_Coyote_Feb2024 Detects Coyote malware samples based on the PE properties | — | — | TLP:WHITE | ✓ | 2024-02-22 | |
| Babuk_Payload_Ransomware Babuk Payload ransomware - Curve25519 + ChaCha20 encryption, RC4 FBI footer key, MakeAmericaGreatAgain mutex | — | — | TLP:WHITE | ✓ | 2026-03-15 | |
| rondodox_elf_multiarch Detects RondoDox (Rondo) botnet ELF multi architecture variants | — | — | TLP:WHITE | ✓ | 2025-12-08 | |
| Luckyware_Infection_Detection Comprehensive detection for Luckyware RAT: covers PE/DLL infection, temp files, and C2 indicators | — | — | TLP:WHITE | ✓ | 2026-01-07 | |
| EXE_ICS_Triton_April2024 Detects Triton ICS malware used to target SIS (Safety Instrumentation Systems) | win.triton | — | TLP:WHITE | ✓ | 2024-04-08 | |
| win_x86_x64_Mirai Detects Mirai | win.mirai | — | TLP:WHITE | ✓ | 2025-01-26 | |
| RABBITHUNT_cls | — | — | TLP:WHITE | ✓ | 2022-06-13 | |
| signed_sys_with_vulnerablity signed_sys_with_vulnerablity | — | — | TLP:WHITE | ✓ | 2023-07-21 | |
| Whitelock_AESGCM_KeySetup_Stub_x64_v1 AES-GCM key and nonce copy stub in 64-bit PE (rep movs patterns) | — | — | TLP:WHITE | ✓ | 2025-10-10 | |
| EXE_Stealer_Elusive_Feb2024 Detects Elusive Stealer malware | — | — | TLP:WHITE | ✓ | 2024-02-26 | |
| Diff_QuasarRAT_01 Identify QuasarRAT samples | — | — | TLP:WHITE | ✓ | 2023-12-27 | |
| Jeevan_Malware_Rewards Detects JeevanReward variants using Technical, Anti-Analysis, and Indian SE keywords | — | — | TLP:WHITE | ✓ | 2026-04-30 | |
| ELF_Toriilike_persist Detects Torii IoT Botnet (stealthier Mirai alternative) | — | — | TLP:WHITE | ✓ | 2025-12-25 | |
| meth_peb_parsing | — | — | TLP:WHITE | ✓ | 2022-06-13 | |
| golang_bin_JCorn_CSC846 CSC-846 Golang detection ruleset | — | — | TLP:WHITE | ✓ | 2024-12-09 | |
| Linux_SSHBruteforce_PRG_OLDTEAM Linux SSH brute-force toolkit (PRG / OLDTEAM), often masquerading as image | — | — | TLP:WHITE | ✓ | 2026-02-06 | |
| test_rule_vldslv | — | — | TLP:WHITE | ✓ | 2026-04-10 | |
| ELF_Backdoor_ZipLine_Feb2024 Detects Zipline backdoor malware samples based on ELF properties and strings | — | — | TLP:WHITE | ✓ | 2024-02-19 | |
| Vile_Ransomware Detects Vile Ransomware, based on family-specific markers and ransom-note strings. | — | — | TLP:WHITE | ✓ | 2026-05-18 | |
| WIN_7IOM204AHBC Detects files and emails containing the windows hostname WIN-7IOM204AHBC. | — | — | TLP:WHITE | ✓ | 2026-03-22 | |
| Dll_Backdoor_FalseFront_Jan2024 Identifies a backdoor known as FalseFront which was used by Peach Sandstorm | — | — | TLP:WHITE | ✓ | 2024-01-25 | |
| AtlasB_Batch_Crypter Detects the AtlasB batch crypter using certutil decode + temp dropper | — | 📦 Packer | — | TLP:WHITE | ✓ | 2025-11-28 |
| BatModifier2 This is a bat file which is setup a game. 49509 | — | — | TLP:WHITE | ✓ | 2025-05-10 | |
| gafgyt_langflow_sbox_cipher Customized Gafgyt/BASHLITE DDoS bot delivered via Langflow CVE-2025-3248; identifies the actor's embedded affine S-box, 16-byte magic key, and LCG-driven stream cipher used for the encrypted C2 protocol | — | 1 CVE | TLP:WHITE | ✓ | 2026-07-15 | |
| yarahub_win_stealc_bytecodes_oct_2023 | win.stealc | — | TLP:WHITE | ✓ | 2023-10-13 | |
| EXE_Stealer_Atlantida Detects the Atlantida Stealer malware based on matched strings | — | — | TLP:WHITE | ✓ | 2024-01-20 | |
| NSVPS_Hydra_SSH_Bruteforce Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot | — | — | TLP:WHITE | ✓ | 2026-07-11 | |
| xlsb_rule Regla para correo malicioso | — | — | TLP:WHITE | ✓ | 2024-04-15 | |
| win_laplas_clipper_9c96 detects unpacked Laplas Clipper | — | — | TLP:WHITE | ✓ | 2022-11-09 | |
| PacketSDK_Proxy_Tunnel_Malware Detects PacketSDK-based proxy/tunnel component used in sysvideo/onedrivesync case | — | — | TLP:WHITE | ✓ | 2025-12-18 | |
| DocBat1 This is a bat file which is a info stealer which take SS of the desktop and sends it to the attackers discord webhook using curl | — | — | TLP:WHITE | ✓ | 2025-05-25 | |
| EXE_Python_Stealer_Jan2024 Detects Python Stealer based on generic strings and high entropy in resources | — | — | TLP:WHITE | ✓ | 2024-01-27 |