← All cheat sheets

YARA

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

YARA is a pattern matching tool for malware identification.
Essential for threat hunting and malware analysis.

INSTALLATION#

# Linux
apt install yara

# Python module
pip install yara-python

BASIC USAGE#


            

SCAN FILE#

yara rules.yar file.exe
yara -r rules.yar directory/        # Recursive
yara rules.yar -p 4 directory/      # 4 threads

SCAN PROCESS#

yara rules.yar 1234                 # PID

SCAN STRING#

echo "test string" | yara rules.yar -

OPTIONS#

-r, --recursive      Scan directories recursively
-s, --strings        Print matching strings
-m, --meta           Print metadata
-g, --tags           Print tags
-n, --negate         Print non-matching rules
-c, --count          Print match count only
-p, --threads N      Use N threads
-t, --tag TAG        Only run rules with tag
-i, --identifier     Only run specified rule
-d VAR=VALUE         Define external variable

RULE STRUCTURE#


            

BASIC RULE#

rule RuleName {
    meta:
        author = "Analyst"
        description = "Detects malware X"
        date = "2024-01-01"

    strings:
        $s1 = "malicious string"
        $s2 = { 4D 5A 90 00 }

    condition:
        any of them
}

RULE SECTIONS#

rule Example {
    meta:           // Metadata (optional)
    strings:        // String definitions
    condition:      // Detection logic (required)
}

STRING TYPES#


            

TEXT STRINGS#

$text1 = "plaintext"
$text2 = "case insensitive" nocase
$text3 = "wide string" wide           # UTF-16
$text4 = "both encodings" ascii wide
$text5 = "full word only" fullword
$text6 = "with escape\x00null"

HEX STRINGS#

$hex1 = { 4D 5A 90 00 }               # MZ header
$hex2 = { 4D 5A ?? ?? }               # Wildcards
$hex3 = { 4D 5A [2-4] 00 }            # Jump 2-4 bytes
$hex4 = { 4D 5A [2-] 00 }             # Jump 2+ bytes
$hex5 = { 4D 5A [-4] 00 }             # Jump 0-4 bytes
$hex6 = { ( 4D | 5A ) 90 }            # Alternatives

REGULAR EXPRESSIONS#

$re1 = /http:\/\/[a-z]+\.com/
$re2 = /[a-zA-Z0-9]{32}/ nocase       # MD5-like
$re3 = /\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/  # IP

CONDITIONS#


            

BASIC CONDITIONS#

condition:
    $s1                               # String exists
    any of them                       # Any string
    all of them                       # All strings
    2 of them                         # At least 2
    $s1 and $s2                       # Both
    $s1 or $s2                        # Either
    not $s1                           # Negation

STRING COUNTING#

condition:
    #s1 > 5                           # More than 5 matches
    #s1 == 2                          # Exactly 2 matches
    @s1[1] < 100                      # First match before offset 100

OFFSETS AND POSITIONS#

condition:
    $s1 at 0                          # At start
    $s1 at 100                        # At offset 100
    $s1 in (0..1024)                  # In range
    @s1 < @s2                         # s1 before s2

FILE SIZE#

condition:
    filesize < 1MB
    filesize > 100KB and filesize < 10MB
    filesize < 500KB

LOOPS AND ITERATIONS#

condition:
    for any of ($s*) : ( $ at 0 )
    for all of them : ( # > 3 )
    for 2 of ($a,$b,$c) : ( @ < 100 )

MODULES#


            

PE MODULE#

import "pe"

rule PEExample {
    condition:
        pe.is_pe and
        pe.number_of_sections > 5 and
        pe.imports("kernel32.dll", "CreateRemoteThread")
}

# PE attributes:
pe.is_pe
pe.is_dll
pe.machine
pe.timestamp
pe.entry_point
pe.image_base
pe.number_of_sections
pe.imports("dll", "function")
pe.exports("function")
pe.characteristics
pe.linker_version.major

ELF MODULE#

import "elf"

rule ELFExample {
    condition:
        elf.type == elf.ET_EXEC
}

HASH MODULE#

import "hash"

rule HashExample {
    condition:
        hash.md5(0, filesize) == "d41d8cd98f00b204e9800998ecf8427e"
        hash.sha256(0, filesize) == "abc..."
}

MATH MODULE#

import "math"

rule EntropyExample {
    condition:
        math.entropy(0, filesize) > 7.5    # High entropy (packed)
}

MALWARE DETECTION EXAMPLES#


            

SUSPICIOUS STRINGS#

rule SuspiciousStrings {
    meta:
        description = "Common malicious indicators"
    strings:
        $s1 = "cmd.exe /c" nocase
        $s2 = "powershell -enc" nocase
        $s3 = "WScript.Shell" nocase
        $s4 = "HKEY_CURRENT_USER" nocase
        $s5 = "CreateRemoteThread"
        $s6 = "VirtualAllocEx"
    condition:
        3 of them
}

PACKED EXECUTABLE#

import "pe"
import "math"

rule PackedPE {
    meta:
        description = "Potentially packed executable"
    condition:
        pe.is_pe and
        math.entropy(0, filesize) > 7.0 and
        pe.number_of_sections < 4
}

MIMIKATZ DETECTION#

rule Mimikatz {
    meta:
        description = "Mimikatz credential dumper"
    strings:
        $s1 = "sekurlsa::logonpasswords" ascii wide nocase
        $s2 = "lsadump::sam" ascii wide nocase
        $s3 = "privilege::debug" ascii wide nocase
        $s4 = "gentilkiwi" ascii wide
        $s5 = "mimikatz" ascii wide nocase
    condition:
        2 of them
}

COBALT STRIKE BEACON#

rule CobaltStrike {
    meta:
        description = "Cobalt Strike indicators"
    strings:
        $s1 = "%s as %s\\%s: %d" ascii
        $s2 = "beacon.dll" ascii
        $s3 = "ReflectiveLoader"
        $h1 = { 4D 5A E8 00 00 00 00 5B 89 DF 52 }
    condition:
        any of them
}

WEBSHELL#

rule PHPWebshell {
    meta:
        description = "PHP webshell indicators"
    strings:
        $s1 = "eval($_" nocase
        $s2 = "base64_decode($_" nocase
        $s3 = "shell_exec(" nocase
        $s4 = "passthru(" nocase
        $s5 = "system($_" nocase
    condition:
        any of them
}

RANSOMWARE INDICATORS#

rule RansomwareIndicators {
    strings:
        $s1 = ".encrypted" nocase
        $s2 = "YOUR FILES HAVE BEEN ENCRYPTED" nocase
        $s3 = "bitcoin" nocase
        $s4 = "CryptGenKey"
        $s5 = "CryptEncrypt"
        $s6 = "README_TO_DECRYPT" nocase
    condition:
        3 of them
}

ORGANIZATION#


            

TAGS#

rule TaggedRule : Malware Trojan RAT {
    condition:
        true
}

# Use: yara -t Malware rules.yar file

INCLUDE FILES#

include "common_rules.yar"
include "./rules/malware/*.yar"

GLOBAL RULES#

global rule GlobalFilter {
    condition:
        filesize < 10MB
}

PRIVATE RULES#

private rule Helper {
    strings:
        $s = "helper"
    condition:
        $s
}

rule Main {
    condition:
        Helper
}

TESTING#

# Test rule syntax
yara -C rules.yar

# Show all matches with details
yara -s -m rules.yar samples/

# Performance profiling
yara -p 4 --profiling rules.yar directory/

QUICK REFERENCE#

yara rules.yar file                  # Scan file
yara -r rules.yar dir/               # Recursive
yara -s rules.yar file               # Show strings
yara -t TAG rules.yar file           # Run tagged rules
yara -d var=value rules.yar file     # External variable
yara -C rules.yar                    # Validate syntax

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.