Skip to content

Commit

Permalink
Create BlackKingdom.yar
Browse files Browse the repository at this point in the history
  • Loading branch information
GossiTheDog authored Mar 25, 2021
1 parent 1e2caa2 commit 66f7442
Showing 1 changed file with 35 additions and 0 deletions.
35 changes: 35 additions & 0 deletions YARA/BlackKingdom.yar
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
rule BlackKingdomExchange
{
strings:
$0 = {250B3D2C742F543A4489F36EA1C503352C36B7883817093D2DB4C0CC1571DE6CDA22CE3385B2A1A3E94AC81771DE2574A7D06D66EEFDA6E449D62D90C32FD65CA1}
$1 = {3F2B2C3249094C8A1A9734E7515D10F78FD1B9339DF1902AC1D4ADE70C27C8A2CA7F3416B7B9F0D10E67519D589B8AD64D6435CC2DF4C2092A4BCEF7053B194A}
$2 = {406357775C42584F11A1610D3A8A31F094FA252BC3E10738BD310D536D3A2F9EC5C21996AC4DCF5237AE3A4467D5678EE2983E4282ADFB1FDEA16352109BA7A7}
$3 = {2B37480D634C799C468B775404368C7B891ADE3A556DF888566EB8CB3ED6F0171B59C35BB57F3B75D9017B7C9D52D1E87F48795AA58A16695B98BAFEAF66A769}
$4 = {294E3B78300A2496C6B4F0D4A8508375D436A3400308CD50A8A10EACB27ACF89EDDF85E2482761FF205576900672B68B0BACBC0EB3B654A9BE343C0ECD4FF45A}
$5 = {2E3F287D4C507D1E08AACF9D41E91F08AA8F3BA83E4783D2BB83EAF340D0FB9E0D81F7DB8F04DEDB82EA333C28BD2DA83EC383EA5317947E78507DEEF47F5F9A}
$6 = {7C2F543460754160C8F29CB98A626FAA4BF5F685B1B3ED98D913F4447C50BD0F98CDFA52698D7CC7858AE236378AF93BA4E670B653DA2CAF98AD28ECED57DEC6}
$7 = {4036506C5B78287289630F9CC90B710C84B7CF63F29DAD2BE124756A121ABC2DA8662F59E840B966A4AF75F60E628F2D2DB2E7691CEA58497F91DE5C58853A6B}
$8 = {603F0D0B24253D0983D54102972C236B5C96911BBC59EF34526C6BCAA707789CD3014DFBB5B8B6C3EDAFE05A79D4227CA5A24CDC6F4DC16533CEEC423B060C5F}
$9 = {60282D4760382DDFF813D752BA0A0FF8996B262DE797649BA5B4FC092466EB6F46B2CDEF47653BBF53618ECE3633FB643BCFEF51ECE99B6D92CC91BDB08596EB}
$10 = {3D302A7E26255A7ACE24202462D9F1D4947B84A822B7B5FBC236CCA45263266DA34B3EDDF4F9B6B9277D7ECB1A871B358ECAEC0C9809623C13106237A5DEEF42}
$11 = {203D6269443A2711F4E170EDB9B183EFAC8E31A0D2E8BAEA675E48C5EEB69991B5DDA237AF95D03E4818E3EFCD0BBD78A187740ECE2B6588C0C29C7227745A1D}
$12 = {242B267640603D427CC31C84D93D28D7A27FDD8536B9158C14964AE46C447F517E258B771653647B35E1688FA1391EFA43DA064F796FAE3C6E6A1565D2CC54FA}
$13 = {5D6F59635E695A662C308A36E418384BEAD7212D2AC5F58BCFF1114DE778CCE59C712CF212E2C961F68D884F34ED3B1EE5681EED73A306F6939AE23C1E248923}
$14 = {0C6C2D764724333940A3ECA1C7629B6B5BDC7E62A1C2E63A14970B8F30B40D037BFB75B6F592291ABD71182EC4741D036C399AA1443CBFCDBFF0B28B3A47459A}
$15 = {267D37705C4E58C823A6AE4416F1CC7453BE12D5B7DA835A2C713B4A0DFC7784EC203CF86F02D9829439B40EB2067973F0DF14A4A99F9B741FC6A7BC2F16683B}
$16 = {0B403023762C57B36E41C9B2E08F0A6AACCF6988D703B839FA8F1559BD96731FF218E1579D13A0573836728F23EA6BDFA7E4BC10FAD5261569863BAEC36DB5B1}
$17 = {28315B59097863A5702209EE8214B36D568EE4B663EB87795D15DA62FDBD6C0286FA14578EF9DBE5B3EA5AE9AF6C140EA85C4C01D99ACFC7192E2D3BBBF0117E}
$18 = {287C3653264758A0BEE29674F59BC469AE4E32F07C6BB8FA19E365410597D63FC23CE52A664C7F80EAB7B158D1AE37D74F5265D0D88F98232FE0E2170F316CCC}
$19 = {7B412C2B7429096E718605334ABBC52956E09226439B3CAA865906827D19483765C0A017D8E30C0B46DE3F9146E9B0B8E04B16DF6352CB7E3D48575DD6566608}
$20 = {292D55782A0C7BEFA1C2F6A8245B0B9FF689F0D1AE326C37860D738FD780C5AB55497304693AC2C7B3EEAEB0220C6BE61E2F91C5FBB192A6A2BBDB939A9684D6}
$21 = {264F6A0952437C2F3BC55E9E554F0D4C0CC936B5958965412A42071C52081636BC196571D90CCC3C07A7C98933378866CE67E033E7546FDA6213DBDE3E0B18C2}
$22 = {60246A31775D4EA321686D965CAD72416FEF2864967B733F9DC3B8149FDA0857A2BFF1E5302564C7CBF6DB7382E81E81BCB1610F5707E36060249F19137530A6}
$23 = {286F32662A6F3166296F33662BEF30E628AB0CE6C27CE443D9E72B37321628EF3216C2FC14280F3016298B198B959B186B147B18858ACD8C22C55EC65AC516C6}
$24 = {3A7D2909442E3386438DE6722DD94B1D1F0166A05581593E3257DC07A6B643D27C82E2B4C5BD14D6997BBA80CD48D854477D892390667E6C37823A789DEAC5DD}
$25 = {7D664A225C386C4ADE43FB4C2981E2B924EBCF4ADE47A13EE901F8F167B39375141A293CFDD995146B1B68BB2918E840F919DDBDF584B43E6922EB9AFECA97C1}
$26 = {5E56592755396B9C6B78EDA93C0FA66B8FA997EEE555E67942F65EBC2AF9E0E22EB2F7465277B88A2E62681A95BCE631F2FC50FDC8A6E59C42B9DA53D1C5103D}
$27 = {296D0C5F503E7886F74261D91806B3B535CC85368D86CE9526C8C7971F55C29DA8CB1B95B138049E9B5C815458CFA2F911ABCB5787472ABDEF8ABE3A68D5F522}
$28 = {2F5155284B214E47E3E50D76E9A5E5DD049BCADF1E9E46D9DCF56D9C3DB0DF4BA9A5BBB0A503DE16565C6E14E7CBCE8FC29E2F7C550FFBDD0C25F4714E144E6C}
condition:
all of them
}

0 comments on commit 66f7442

Please sign in to comment.