mandiant / mandiant/capa-rules

triage PATCHCORD malware for new capa rules

Open
#1,176 1 comment 0 reactions 0 assignees View on GitHub
rule idea
Dominant language
No language data
Stars
736
Forks
245
Avg merge
4d 53m
Merged PRs (30d)
2

Description

samples from here: https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/

including at least 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a

Contributor guide

Open the contributing guide

Research direction

Start with the linked PATCHCORD report and the sample identified by hash 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a. Triage the sample for capabilities that can be represented as capa rules; done means the relevant new rules are added and cover the identified behavior.

Written by the indexing model from the issue text.

Assessment

Domain
reverse-engineering, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.