YARA "dotnet" module now available for Livehunt and Retrohunt
#1
Information 
Quote:
[Image: Logo_VT_Horizontal.png]


Good news for all threat hunters! As announced in our latest release notes, the “dotnet” YARA module is already available both for your Livehunt and Retrohunt rules. This module allows inspecting features and characteristics of .NET executable files, like GUIDs used, .NET assemblies metadata, resources and so on.

As an example, the following YARA rule published by AlienVault uses different features provided by the “dotnet” module for detecting Shrug ransomware:
 
Code:
import "dotnet"
rule ShrugRansomware {
meta:
author = "AlienVault Labs"

strings:
$bitcoin_address = "1Hr1grgH9ViEgUx73iRRJLVKH3PFjUteNx"
$s1 = "upoldhash.php"
$s2 = "HarmedFiles"
$s3 = "ShrugDecryptor"
$s4 = "SHRUG2"
$pdb1 = "\\Debug\\ShrugTwo.pdb"
$pdb2 = "\\Debug\\Shrug.pdb"

condition:
uint16(0) == 0x5A4D and
dotnet.number_of_guids > 0 and
(
dotnet.typelib == "a6ab6b1f-b144-4920-be42-bb90ec6fc22e"
or $bitcoin_address
or 2 of ($s*)
or any of ($pdb*)
)
}

The “dotnet” module is not exactly new: it has been growing its own fan club since YARA 3.6.0. However, it was not included in the default YARA build nor enabled in VirusTotal services… until now! You can find more information about this module in the official YARA documentation.

We want to use the opportunity to thank Wesley Shields, the module’s original author, for this great contribution to YARA.

We hope these changes will make life easier for the malware research community and, as usual, we would hear any feedback from you.

Happy hunting!
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
qBittorrent v5.2.0
Sun May 03rd 2026 ...harlan4096 — 06:45
AMD Ryzen AI Max+ PRO 495 leaks out, fea...
AMD Ryzen AI Max+ ...harlan4096 — 06:44
K-Lite Codec Pack 19.6.8 / 19.6.9 Update
Changes in 19.6.9 ...harlan4096 — 10:29
Privazer 4.0.121 (02 May 2026)
v4.0.121 (02 May 2...harlan4096 — 10:27
Sandboxie 1.17.5 / 5.72.5
Sandboxie-Plus v1....harlan4096 — 10:26

[-]
Birthdays
Today's Birthdays
avatar (44)nikitaxople
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (45)xclubDum
avatar (41)Stewartanilm
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>