SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 3,932 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 3,932 new IOCs ingested in last 24h
🧬

YARA Rules

File-based detection rules from YARAify/YARAhub — search, filter, and drill into CVE/malware-family/MITRE ATT&CK correlation per rule.

Tracked Rules
1,132
YARAify / YARAhub
With CVE Correlation
13
yara_rule_links
By Category
packer
12
webshell
7
cryptominer
5
email
5
By TLP
TLP:WHITE×1127
TLP:AMBER×2
🧬 YARA Rule Browser1,132 results
YARAify · abuse.ch
🔍
1,132 rules
Page 1 / 23 · showing 1–50
easyforme_infostealer—
🕵️ Stealer
—TLP:WHITE✓2025-05-29
HKTL_Gsocket_Config_Blob
gs-netcat embedded operator config (664-byte gsnc_config structure)
—
—TLP:WHITE✓2026-08-23
Foxveil_Stage2_Zsh_OctalBeacon
Foxveil ClickFix stage-2 zsh: octal-printf strings, /api/metrics/run?event= beacon with user and BuildID headers, payload fetched to /tmp and run
—
—TLP:WHITE✓2026-09-18
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
Detects Naming Pattern used by ConfuserEx. ConfuserEx is a widely used open source obfuscator often found in malware
—
—TLP:WHITE✓2024-01-03
JAVA_Malware_Unknown_ForgeAuto_a107966c_Extrait
Detects Unknown (class, etat extrait)
—
—TLP:WHITE✓2026-09-25
loader_win_bumblebee
Find BumbleBee samples based on specific strings
win.bumblebee
—TLP:WHITE✓2022-06-02
Win32_Trojan_ShinyHunters_Signed_Payload
Detects Windows executables signed with certificates issued to Tobias Weihmann Software Development OU via Sectigo, observed in ShinyHunters / UNC6240 campaigns.
—
—TLP:WHITE✓2026-09-26
SUS_Unsigned_APPX_MSIX_Installer_Feb23
Detects suspicious, unsigned Microsoft Windows APPX/MSIX Installer Packages
—
—TLP:WHITE✓2023-02-01
LNK_plugx_mustang_panda
Detects LNK files with embedded obfuscated PowerShell scripts that extract and execute embedded payloads
—
—TLP:WHITE✓2026-01-12
HellsUchecker_Shellcode_Loader
HellsUchecker x64 shellcode loader - position-independent code with SipHash-variant CTR cipher and aPLib decompression. Targets raw shellcode as injected via Hell's Gate NtCreateSection.
—
—TLP:WHITE✓2026-03-11
JAVA_Malware_Unknown_ForgeAuto_b915704e
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_5cf95c47
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
HUNT_NET_Loader_BitmapStego_LateBindingInvoke
Hunting: .NET loader reading pixel data from a resource Bitmap, loading an assembly and invoking its first exported method via VB LateBinding
—
—TLP:WHITE✓2026-09-26
dependsonpythonailib
Hunts for dependencies on Python AI libraries
—
—TLP:WHITE✓2025-05-10
win_valleyrat_stage1_heavy_loader
Detects ValleyRAT Stage-1 Inflated Loader (Silver Fox)
—
—TLP:WHITE✓2026-08-08
JAVA_Malware_Unknown_ForgeAuto_076f344d
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_be757529
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-20
Hunt_Obfuscated_Localhost_ROT
Detects obfuscated/rotated 127.0.0.1 strings while excluding raw plaintext
—
—TLP:WHITE✓2026-08-17
shubstealer_stage2_applescript
Detects SHubStealer stage-2 AppleScript payload by C2 endpoints and capability markers
—
—TLP:WHITE✓2026-04-17
MALDAC
Detects samples designed to use WDAC to disable AV/EDR. False positives may occur.
—
—TLP:WHITE✓2025-11-18
JAVA_Malware_Unknown_ForgeAuto_df6b6b71
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_e1eeca57
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
globalnet_files
Detect PE files compiled with PyInstaller with AntiDecompilation string. Observed in GlobalNet botnet campaign.
—
—TLP:WHITE✓2024-01-28
MULTI_Sample_Unique_c6a5d146
Detects Unknown (inconnu, etat binaire)
—
—TLP:WHITE✓2026-09-25
APT_Bitter_Maldoc_Verify
Detects Bitter (T-APT-17) shellcode in oleObject (CVE-2018-0798)
—
📄 Maldoc
1 CVETLP:WHITE✓2022-06-01
EXE_ICS_IronGate_April2024
Detects Iron Gate ICS malware targeting simulation environment which appears to be a PoC
—
—TLP:WHITE✓2024-04-07
JAVA_Malware_Unknown_ForgeAuto_f9815677
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
BadIIS_JKornevHidden
attempts to match the strings found in BadIIS variant of the JKornevHidden rootkit
—
—TLP:WHITE✓2025-09-20
JAVA_Malware_Unknown_ForgeAuto_17d5a043
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_58b146ce
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_2218d235
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_a9f39fd8
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
win_originbot
Detects OriginBot(net) / OriginLoader malware.
—
—TLP:WHITE✓2024-01-04
TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
—
🛡️ Anti-Debug/VM
—TLP:WHITE✓2026-03-18
DLL_RWX_S_Signed_Search
Detects RWX-S signed DLLs. This verifies that the image contains a signature, not that it is valid.
—
—TLP:WHITE✓2024-09-19
MintsLoader_Victim_Profiler
MintsLoader/TAG-124 victim profiler - sandbox detection and scoring
—
—TLP:WHITE✓2026-03-08
JAVA_Malware_SilentNet_ForgeAuto_9343a597_Extrait
Detects SilentNet (class, etat extrait)
—
—TLP:WHITE✓2026-09-21
DLL_BankingTrojan_Coyote_Feb2024
Detects Coyote malware samples based on the PE properties
—
—TLP:WHITE✓2024-02-22
Malware_PE_NET_KoiLoader
Detects Koi Loader .NET executables packed with Confuser featuring specific mutex, assembly metadata, and unmanaged DLL imports
—
—TLP:WHITE✓2026-09-13
JAVA_Malware_Unknown_ForgeAuto_841e376a
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
WEBSHELL_PHP_byte_bunk_shell
BYTE_BUNK Shell v4.0 - PHP webshell with OS command execution, MySQL access and a reverse-shell socket, distributed as the root index.php of a repackaged copy of the legitimate WordPress plugin Protect Uploads (Alticreation). Probes for a surviving exec function and clears open_basedir, disable_functions, safe_mode and suhosin.executor.disable_eval.
—
🐚 Webshell
—TLP:WHITE✓2026-09-23
Babuk_Payload_Ransomware
Babuk Payload ransomware - Curve25519 + ChaCha20 encryption, RC4 FBI footer key, MakeAmericaGreatAgain mutex
—
—TLP:WHITE✓2026-03-15
rondodox_elf_multiarch
Detects RondoDox (Rondo) botnet ELF multi architecture variants
—
—TLP:WHITE✓2025-12-08
Luckyware_Infection_Detection
Comprehensive detection for Luckyware RAT: covers PE/DLL infection, temp files, and C2 indicators
—
—TLP:WHITE✓2026-01-07
EXE_ICS_Triton_April2024
Detects Triton ICS malware used to target SIS (Safety Instrumentation Systems)
win.triton
—TLP:WHITE✓2024-04-08
JAVA_Malware_Unknown_ForgeAuto_8135c74d_Extrait
Detects Unknown (class, etat extrait)
—
—TLP:WHITE✓2026-09-25
JAVA_Malware_Unknown_ForgeAuto_a0426def
Detects Unknown (class, etat binaire)
—
—TLP:WHITE✓2026-09-25
SCRIPT_Sample_Unique_fc339692
Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
—
—TLP:WHITE✓2026-09-18
win_x86_x64_Mirai
Detects Mirai
win.mirai
—TLP:WHITE✓2025-01-26
RABBITHUNT_cls—
—TLP:WHITE✓2022-06-13