capa-rules
capa-rules copied to clipboard
Idea - Malicious Libraries in TRJ_BANKER
Hi,
what is the best way to create rule/rules to detect these suspicious libraries?
Would it be a rule for each library?
Ref.: https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/
https://twitter.com/johnk3r/status/1558600148309131266
Yes, one rule per library fits best with our current approach.
Additionally, we could add a parent rule that combines these, however, that's optional and likely doesn't add much value but may require more maintenance.
Would you mind submitting a PR based on your existing rule(s)?
Additional reference: https://gist.github.com/mr-tz/46983e141a6f6ac9654b75ec86748a7d