02.04.2017 Views

Daniel Plohmann daniel.plohmann@fkie.fraunhofer.de @push_pnx @malpedia

e4kWdgu

e4kWdgu

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Malpedia: Status Quo<br />

YaraRules.com vs. Malpedia<br />

I<strong>de</strong>ally, these or more would be hit<br />

337 families 115 40<br />

212<br />

• YaraRules.com results:<br />

actually hit<br />

• 95 of 1,611 malware rules produce matches against 67 families of malpedia<br />

• For some families, multiple rules exist and hit (5x BlackSha<strong>de</strong>s RAT, 5x Codoso, 3x Turla, …)<br />

• 5 rules (6%) produce False Positives against 3 or more families<br />

• Conditions are chosen so wi<strong>de</strong> that they allow one or more FP strings as a group to already fulfil the rule<br />

• Example: „data_inject“ (generic for many webinjects, matches a bunch of bankers)<br />

• Example: „mario“ AND „RFB 003.033“ AND „FIXME“ (matches basically every Zeus offspring)<br />

• 19 families (28%) were hit incompletely<br />

• On average they match only 29.58% of the samples present for the respective family.<br />

51<br />

© Cyber Analysis and Defense Department, Fraunhofer FKIE

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!