🧬
YARA Rules
File-based detection rules from YARAify/YARAhub — search, filter, and drill into CVE/malware-family/MITRE ATT&CK correlation per rule.
Tracked Rules
1,132
YARAify / YARAhub
With CVE Correlation
13
yara_rule_links
By Category
packer
12
webshell
7
cryptominer
5
email
5
By TLP
TLP:WHITE×1127
TLP:AMBER×2
🧬 YARA Rule Browser1,132 results
YARAify · abuse.ch
🔍
1,132 rulesPage 1 / 23 · showing 1–50
| easyforme_infostealer | — | 🕵️ Stealer | — | TLP:WHITE | ✓ | 2025-05-29 |
| HKTL_Gsocket_Config_Blob gs-netcat embedded operator config (664-byte gsnc_config structure) | — | — | TLP:WHITE | ✓ | 2026-08-23 | |
| Foxveil_Stage2_Zsh_OctalBeacon Foxveil ClickFix stage-2 zsh: octal-printf strings, /api/metrics/run?event= beacon with user and BuildID headers, payload fetched to /tmp and run | — | — | TLP:WHITE | ✓ | 2026-09-18 | |
| SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 Detects Naming Pattern used by ConfuserEx. ConfuserEx is a widely used open source obfuscator often found in malware | — | — | TLP:WHITE | ✓ | 2024-01-03 | |
| JAVA_Malware_Unknown_ForgeAuto_a107966c_Extrait Detects Unknown (class, etat extrait) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| loader_win_bumblebee Find BumbleBee samples based on specific strings | win.bumblebee | — | TLP:WHITE | ✓ | 2022-06-02 | |
| Win32_Trojan_ShinyHunters_Signed_Payload Detects Windows executables signed with certificates issued to Tobias Weihmann Software Development OU via Sectigo, observed in ShinyHunters / UNC6240 campaigns. | — | — | TLP:WHITE | ✓ | 2026-09-26 | |
| SUS_Unsigned_APPX_MSIX_Installer_Feb23 Detects suspicious, unsigned Microsoft Windows APPX/MSIX Installer Packages | — | — | TLP:WHITE | ✓ | 2023-02-01 | |
| LNK_plugx_mustang_panda Detects LNK files with embedded obfuscated PowerShell scripts that extract and execute embedded payloads | — | — | TLP:WHITE | ✓ | 2026-01-12 | |
| HellsUchecker_Shellcode_Loader HellsUchecker x64 shellcode loader - position-independent code with SipHash-variant CTR cipher and aPLib decompression. Targets raw shellcode as injected via Hell's Gate NtCreateSection. | — | — | TLP:WHITE | ✓ | 2026-03-11 | |
| JAVA_Malware_Unknown_ForgeAuto_b915704e Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_5cf95c47 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| HUNT_NET_Loader_BitmapStego_LateBindingInvoke Hunting: .NET loader reading pixel data from a resource Bitmap, loading an assembly and invoking its first exported method via VB LateBinding | — | — | TLP:WHITE | ✓ | 2026-09-26 | |
| dependsonpythonailib Hunts for dependencies on Python AI libraries | — | — | TLP:WHITE | ✓ | 2025-05-10 | |
| win_valleyrat_stage1_heavy_loader Detects ValleyRAT Stage-1 Inflated Loader (Silver Fox) | — | — | TLP:WHITE | ✓ | 2026-08-08 | |
| JAVA_Malware_Unknown_ForgeAuto_076f344d Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_be757529 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-20 | |
| Hunt_Obfuscated_Localhost_ROT Detects obfuscated/rotated 127.0.0.1 strings while excluding raw plaintext | — | — | TLP:WHITE | ✓ | 2026-08-17 | |
| shubstealer_stage2_applescript Detects SHubStealer stage-2 AppleScript payload by C2 endpoints and capability markers | — | — | TLP:WHITE | ✓ | 2026-04-17 | |
| MALDAC Detects samples designed to use WDAC to disable AV/EDR. False positives may occur. | — | — | TLP:WHITE | ✓ | 2025-11-18 | |
| JAVA_Malware_Unknown_ForgeAuto_df6b6b71 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_e1eeca57 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| globalnet_files Detect PE files compiled with PyInstaller with AntiDecompilation string. Observed in GlobalNet botnet campaign. | — | — | TLP:WHITE | ✓ | 2024-01-28 | |
| MULTI_Sample_Unique_c6a5d146 Detects Unknown (inconnu, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| APT_Bitter_Maldoc_Verify Detects Bitter (T-APT-17) shellcode in oleObject (CVE-2018-0798) | — | 📄 Maldoc | 1 CVE | TLP:WHITE | ✓ | 2022-06-01 |
| EXE_ICS_IronGate_April2024 Detects Iron Gate ICS malware targeting simulation environment which appears to be a PoC | — | — | TLP:WHITE | ✓ | 2024-04-07 | |
| JAVA_Malware_Unknown_ForgeAuto_f9815677 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| BadIIS_JKornevHidden attempts to match the strings found in BadIIS variant of the JKornevHidden rootkit | — | — | TLP:WHITE | ✓ | 2025-09-20 | |
| JAVA_Malware_Unknown_ForgeAuto_17d5a043 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_58b146ce Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_2218d235 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_a9f39fd8 Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| win_originbot Detects OriginBot(net) / OriginLoader malware. | — | — | TLP:WHITE | ✓ | 2024-01-04 | |
| TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments | — | 🛡️ Anti-Debug/VM | — | TLP:WHITE | ✓ | 2026-03-18 |
| DLL_RWX_S_Signed_Search Detects RWX-S signed DLLs. This verifies that the image contains a signature, not that it is valid. | — | — | TLP:WHITE | ✓ | 2024-09-19 | |
| MintsLoader_Victim_Profiler MintsLoader/TAG-124 victim profiler - sandbox detection and scoring | — | — | TLP:WHITE | ✓ | 2026-03-08 | |
| JAVA_Malware_SilentNet_ForgeAuto_9343a597_Extrait Detects SilentNet (class, etat extrait) | — | — | TLP:WHITE | ✓ | 2026-09-21 | |
| DLL_BankingTrojan_Coyote_Feb2024 Detects Coyote malware samples based on the PE properties | — | — | TLP:WHITE | ✓ | 2024-02-22 | |
| Malware_PE_NET_KoiLoader Detects Koi Loader .NET executables packed with Confuser featuring specific mutex, assembly metadata, and unmanaged DLL imports | — | — | TLP:WHITE | ✓ | 2026-09-13 | |
| JAVA_Malware_Unknown_ForgeAuto_841e376a Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| WEBSHELL_PHP_byte_bunk_shell BYTE_BUNK Shell v4.0 - PHP webshell with OS command execution, MySQL access and a reverse-shell socket, distributed as the root index.php of a repackaged copy of the legitimate WordPress plugin Protect Uploads (Alticreation). Probes for a surviving exec function and clears open_basedir, disable_functions, safe_mode and suhosin.executor.disable_eval. | — | 🐚 Webshell | — | TLP:WHITE | ✓ | 2026-09-23 |
| Babuk_Payload_Ransomware Babuk Payload ransomware - Curve25519 + ChaCha20 encryption, RC4 FBI footer key, MakeAmericaGreatAgain mutex | — | — | TLP:WHITE | ✓ | 2026-03-15 | |
| rondodox_elf_multiarch Detects RondoDox (Rondo) botnet ELF multi architecture variants | — | — | TLP:WHITE | ✓ | 2025-12-08 | |
| Luckyware_Infection_Detection Comprehensive detection for Luckyware RAT: covers PE/DLL infection, temp files, and C2 indicators | — | — | TLP:WHITE | ✓ | 2026-01-07 | |
| EXE_ICS_Triton_April2024 Detects Triton ICS malware used to target SIS (Safety Instrumentation Systems) | win.triton | — | TLP:WHITE | ✓ | 2024-04-08 | |
| JAVA_Malware_Unknown_ForgeAuto_8135c74d_Extrait Detects Unknown (class, etat extrait) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| JAVA_Malware_Unknown_ForgeAuto_a0426def Detects Unknown (class, etat binaire) | — | — | TLP:WHITE | ✓ | 2026-09-25 | |
| SCRIPT_Sample_Unique_fc339692 Specimen unique (soumission Bazaar) - strings distinctifs propres au sample | — | — | TLP:WHITE | ✓ | 2026-09-18 | |
| win_x86_x64_Mirai Detects Mirai | win.mirai | — | TLP:WHITE | ✓ | 2025-01-26 | |
| RABBITHUNT_cls | — | — | TLP:WHITE | ✓ | 2022-06-13 |