YARA
YARA is a pattern matching tool for malware identification. Essential for threat hunting and malware analysis.
INSTALLATION#
# Linux apt install yara # Python module pip install yara-python
BASIC USAGE#
SCAN FILE#
yara rules.yar file.exe yara -r rules.yar directory/ # Recursive yara rules.yar -p 4 directory/ # 4 threads
SCAN PROCESS#
yara rules.yar 1234 # PID
SCAN STRING#
echo "test string" | yara rules.yar -
OPTIONS#
-r, --recursive Scan directories recursively -s, --strings Print matching strings -m, --meta Print metadata -g, --tags Print tags -n, --negate Print non-matching rules -c, --count Print match count only -p, --threads N Use N threads -t, --tag TAG Only run rules with tag -i, --identifier Only run specified rule -d VAR=VALUE Define external variable
RULE STRUCTURE#
BASIC RULE#
rule RuleName {
meta:
author = "Analyst"
description = "Detects malware X"
date = "2024-01-01"
strings:
$s1 = "malicious string"
$s2 = { 4D 5A 90 00 }
condition:
any of them
}
RULE SECTIONS#
rule Example {
meta: // Metadata (optional)
strings: // String definitions
condition: // Detection logic (required)
}
STRING TYPES#
TEXT STRINGS#
$text1 = "plaintext" $text2 = "case insensitive" nocase $text3 = "wide string" wide # UTF-16 $text4 = "both encodings" ascii wide $text5 = "full word only" fullword $text6 = "with escape\x00null"
HEX STRINGS#
$hex1 = { 4D 5A 90 00 } # MZ header
$hex2 = { 4D 5A ?? ?? } # Wildcards
$hex3 = { 4D 5A [2-4] 00 } # Jump 2-4 bytes
$hex4 = { 4D 5A [2-] 00 } # Jump 2+ bytes
$hex5 = { 4D 5A [-4] 00 } # Jump 0-4 bytes
$hex6 = { ( 4D | 5A ) 90 } # Alternatives
REGULAR EXPRESSIONS#
$re1 = /http:\/\/[a-z]+\.com/
$re2 = /[a-zA-Z0-9]{32}/ nocase # MD5-like
$re3 = /\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/ # IP
CONDITIONS#
BASIC CONDITIONS#
condition:
$s1 # String exists
any of them # Any string
all of them # All strings
2 of them # At least 2
$s1 and $s2 # Both
$s1 or $s2 # Either
not $s1 # Negation
STRING COUNTING#
condition:
#s1 > 5 # More than 5 matches
#s1 == 2 # Exactly 2 matches
@s1[1] < 100 # First match before offset 100
OFFSETS AND POSITIONS#
condition:
$s1 at 0 # At start
$s1 at 100 # At offset 100
$s1 in (0..1024) # In range
@s1 < @s2 # s1 before s2
FILE SIZE#
condition:
filesize < 1MB
filesize > 100KB and filesize < 10MB
filesize < 500KB
LOOPS AND ITERATIONS#
condition:
for any of ($s*) : ( $ at 0 )
for all of them : ( # > 3 )
for 2 of ($a,$b,$c) : ( @ < 100 )
MODULES#
PE MODULE#
import "pe"
rule PEExample {
condition:
pe.is_pe and
pe.number_of_sections > 5 and
pe.imports("kernel32.dll", "CreateRemoteThread")
}
# PE attributes:
pe.is_pe
pe.is_dll
pe.machine
pe.timestamp
pe.entry_point
pe.image_base
pe.number_of_sections
pe.imports("dll", "function")
pe.exports("function")
pe.characteristics
pe.linker_version.major
ELF MODULE#
import "elf"
rule ELFExample {
condition:
elf.type == elf.ET_EXEC
}
HASH MODULE#
import "hash"
rule HashExample {
condition:
hash.md5(0, filesize) == "d41d8cd98f00b204e9800998ecf8427e"
hash.sha256(0, filesize) == "abc..."
}
MATH MODULE#
import "math"
rule EntropyExample {
condition:
math.entropy(0, filesize) > 7.5 # High entropy (packed)
}
MALWARE DETECTION EXAMPLES#
SUSPICIOUS STRINGS#
rule SuspiciousStrings {
meta:
description = "Common malicious indicators"
strings:
$s1 = "cmd.exe /c" nocase
$s2 = "powershell -enc" nocase
$s3 = "WScript.Shell" nocase
$s4 = "HKEY_CURRENT_USER" nocase
$s5 = "CreateRemoteThread"
$s6 = "VirtualAllocEx"
condition:
3 of them
}
PACKED EXECUTABLE#
import "pe"
import "math"
rule PackedPE {
meta:
description = "Potentially packed executable"
condition:
pe.is_pe and
math.entropy(0, filesize) > 7.0 and
pe.number_of_sections < 4
}
MIMIKATZ DETECTION#
rule Mimikatz {
meta:
description = "Mimikatz credential dumper"
strings:
$s1 = "sekurlsa::logonpasswords" ascii wide nocase
$s2 = "lsadump::sam" ascii wide nocase
$s3 = "privilege::debug" ascii wide nocase
$s4 = "gentilkiwi" ascii wide
$s5 = "mimikatz" ascii wide nocase
condition:
2 of them
}
COBALT STRIKE BEACON#
rule CobaltStrike {
meta:
description = "Cobalt Strike indicators"
strings:
$s1 = "%s as %s\\%s: %d" ascii
$s2 = "beacon.dll" ascii
$s3 = "ReflectiveLoader"
$h1 = { 4D 5A E8 00 00 00 00 5B 89 DF 52 }
condition:
any of them
}
WEBSHELL#
rule PHPWebshell {
meta:
description = "PHP webshell indicators"
strings:
$s1 = "eval($_" nocase
$s2 = "base64_decode($_" nocase
$s3 = "shell_exec(" nocase
$s4 = "passthru(" nocase
$s5 = "system($_" nocase
condition:
any of them
}
RANSOMWARE INDICATORS#
rule RansomwareIndicators {
strings:
$s1 = ".encrypted" nocase
$s2 = "YOUR FILES HAVE BEEN ENCRYPTED" nocase
$s3 = "bitcoin" nocase
$s4 = "CryptGenKey"
$s5 = "CryptEncrypt"
$s6 = "README_TO_DECRYPT" nocase
condition:
3 of them
}
ORGANIZATION#
TAGS#
rule TaggedRule : Malware Trojan RAT {
condition:
true
}
# Use: yara -t Malware rules.yar file
INCLUDE FILES#
include "common_rules.yar" include "./rules/malware/*.yar"
GLOBAL RULES#
global rule GlobalFilter {
condition:
filesize < 10MB
}
PRIVATE RULES#
private rule Helper {
strings:
$s = "helper"
condition:
$s
}
rule Main {
condition:
Helper
}
TESTING#
# Test rule syntax yara -C rules.yar # Show all matches with details yara -s -m rules.yar samples/ # Performance profiling yara -p 4 --profiling rules.yar directory/
QUICK REFERENCE#
yara rules.yar file # Scan file yara -r rules.yar dir/ # Recursive yara -s rules.yar file # Show strings yara -t TAG rules.yar file # Run tagged rules yara -d var=value rules.yar file # External variable yara -C rules.yar # Validate syntax
YARA CHEATSHEET
===============
Source: https://cheatsheet.johlem.net
YARA is a pattern matching tool for malware identification.
Essential for threat hunting and malware analysis.
INSTALLATION
------------
# Linux
apt install yara
# Python module
pip install yara-python
BASIC USAGE
===========
SCAN FILE
---------
yara rules.yar file.exe
yara -r rules.yar directory/ # Recursive
yara rules.yar -p 4 directory/ # 4 threads
SCAN PROCESS
------------
yara rules.yar 1234 # PID
SCAN STRING
-----------
echo "test string" | yara rules.yar -
OPTIONS
-------
-r, --recursive Scan directories recursively
-s, --strings Print matching strings
-m, --meta Print metadata
-g, --tags Print tags
-n, --negate Print non-matching rules
-c, --count Print match count only
-p, --threads N Use N threads
-t, --tag TAG Only run rules with tag
-i, --identifier Only run specified rule
-d VAR=VALUE Define external variable
RULE STRUCTURE
==============
BASIC RULE
----------
rule RuleName {
meta:
author = "Analyst"
description = "Detects malware X"
date = "2024-01-01"
strings:
$s1 = "malicious string"
$s2 = { 4D 5A 90 00 }
condition:
any of them
}
RULE SECTIONS
-------------
rule Example {
meta: // Metadata (optional)
strings: // String definitions
condition: // Detection logic (required)
}
STRING TYPES
============
TEXT STRINGS
------------
$text1 = "plaintext"
$text2 = "case insensitive" nocase
$text3 = "wide string" wide # UTF-16
$text4 = "both encodings" ascii wide
$text5 = "full word only" fullword
$text6 = "with escape\x00null"
HEX STRINGS
-----------
$hex1 = { 4D 5A 90 00 } # MZ header
$hex2 = { 4D 5A ?? ?? } # Wildcards
$hex3 = { 4D 5A [2-4] 00 } # Jump 2-4 bytes
$hex4 = { 4D 5A [2-] 00 } # Jump 2+ bytes
$hex5 = { 4D 5A [-4] 00 } # Jump 0-4 bytes
$hex6 = { ( 4D | 5A ) 90 } # Alternatives
REGULAR EXPRESSIONS
-------------------
$re1 = /http:\/\/[a-z]+\.com/
$re2 = /[a-zA-Z0-9]{32}/ nocase # MD5-like
$re3 = /\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/ # IP
CONDITIONS
==========
BASIC CONDITIONS
----------------
condition:
$s1 # String exists
any of them # Any string
all of them # All strings
2 of them # At least 2
$s1 and $s2 # Both
$s1 or $s2 # Either
not $s1 # Negation
STRING COUNTING
---------------
condition:
#s1 > 5 # More than 5 matches
#s1 == 2 # Exactly 2 matches
@s1[1] < 100 # First match before offset 100
OFFSETS AND POSITIONS
---------------------
condition:
$s1 at 0 # At start
$s1 at 100 # At offset 100
$s1 in (0..1024) # In range
@s1 < @s2 # s1 before s2
FILE SIZE
---------
condition:
filesize < 1MB
filesize > 100KB and filesize < 10MB
filesize < 500KB
LOOPS AND ITERATIONS
--------------------
condition:
for any of ($s*) : ( $ at 0 )
for all of them : ( # > 3 )
for 2 of ($a,$b,$c) : ( @ < 100 )
MODULES
=======
PE MODULE
---------
import "pe"
rule PEExample {
condition:
pe.is_pe and
pe.number_of_sections > 5 and
pe.imports("kernel32.dll", "CreateRemoteThread")
}
# PE attributes:
pe.is_pe
pe.is_dll
pe.machine
pe.timestamp
pe.entry_point
pe.image_base
pe.number_of_sections
pe.imports("dll", "function")
pe.exports("function")
pe.characteristics
pe.linker_version.major
ELF MODULE
----------
import "elf"
rule ELFExample {
condition:
elf.type == elf.ET_EXEC
}
HASH MODULE
-----------
import "hash"
rule HashExample {
condition:
hash.md5(0, filesize) == "d41d8cd98f00b204e9800998ecf8427e"
hash.sha256(0, filesize) == "abc..."
}
MATH MODULE
-----------
import "math"
rule EntropyExample {
condition:
math.entropy(0, filesize) > 7.5 # High entropy (packed)
}
MALWARE DETECTION EXAMPLES
==========================
SUSPICIOUS STRINGS
------------------
rule SuspiciousStrings {
meta:
description = "Common malicious indicators"
strings:
$s1 = "cmd.exe /c" nocase
$s2 = "powershell -enc" nocase
$s3 = "WScript.Shell" nocase
$s4 = "HKEY_CURRENT_USER" nocase
$s5 = "CreateRemoteThread"
$s6 = "VirtualAllocEx"
condition:
3 of them
}
PACKED EXECUTABLE
-----------------
import "pe"
import "math"
rule PackedPE {
meta:
description = "Potentially packed executable"
condition:
pe.is_pe and
math.entropy(0, filesize) > 7.0 and
pe.number_of_sections < 4
}
MIMIKATZ DETECTION
------------------
rule Mimikatz {
meta:
description = "Mimikatz credential dumper"
strings:
$s1 = "sekurlsa::logonpasswords" ascii wide nocase
$s2 = "lsadump::sam" ascii wide nocase
$s3 = "privilege::debug" ascii wide nocase
$s4 = "gentilkiwi" ascii wide
$s5 = "mimikatz" ascii wide nocase
condition:
2 of them
}
COBALT STRIKE BEACON
--------------------
rule CobaltStrike {
meta:
description = "Cobalt Strike indicators"
strings:
$s1 = "%s as %s\\%s: %d" ascii
$s2 = "beacon.dll" ascii
$s3 = "ReflectiveLoader"
$h1 = { 4D 5A E8 00 00 00 00 5B 89 DF 52 }
condition:
any of them
}
WEBSHELL
--------
rule PHPWebshell {
meta:
description = "PHP webshell indicators"
strings:
$s1 = "eval($_" nocase
$s2 = "base64_decode($_" nocase
$s3 = "shell_exec(" nocase
$s4 = "passthru(" nocase
$s5 = "system($_" nocase
condition:
any of them
}
RANSOMWARE INDICATORS
---------------------
rule RansomwareIndicators {
strings:
$s1 = ".encrypted" nocase
$s2 = "YOUR FILES HAVE BEEN ENCRYPTED" nocase
$s3 = "bitcoin" nocase
$s4 = "CryptGenKey"
$s5 = "CryptEncrypt"
$s6 = "README_TO_DECRYPT" nocase
condition:
3 of them
}
ORGANIZATION
============
TAGS
----
rule TaggedRule : Malware Trojan RAT {
condition:
true
}
# Use: yara -t Malware rules.yar file
INCLUDE FILES
-------------
include "common_rules.yar"
include "./rules/malware/*.yar"
GLOBAL RULES
------------
global rule GlobalFilter {
condition:
filesize < 10MB
}
PRIVATE RULES
-------------
private rule Helper {
strings:
$s = "helper"
condition:
$s
}
rule Main {
condition:
Helper
}
TESTING
=======
# Test rule syntax
yara -C rules.yar
# Show all matches with details
yara -s -m rules.yar samples/
# Performance profiling
yara -p 4 --profiling rules.yar directory/
QUICK REFERENCE
---------------
yara rules.yar file # Scan file
yara -r rules.yar dir/ # Recursive
yara -s rules.yar file # Show strings
yara -t TAG rules.yar file # Run tagged rules
yara -d var=value rules.yar file # External variable
yara -C rules.yar # Validate syntax
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.