-
-
Save oxidizeddreams/a3d6b5a91a4c21bd94ef5400a2c3e97e to your computer and use it in GitHub Desktop.
very simple yara to find xmrig Crypto-Miners
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
rule MinerGate | |
{ | |
strings: | |
$a1 = "minergate.com" | |
condition: | |
$a1 | |
} | |
rule MoneroOrg | |
{ | |
strings: | |
$a1 = "POOL.MONERO.ORG" | |
$a2 = "pool.monero.org" | |
condition: | |
$a1 or $a2 | |
} | |
rule cryptonotepool | |
{ | |
strings: | |
$a1 = "cryptonotepool.org.uk" | |
condition: | |
$a1 | |
} | |
rule minexmr | |
{ | |
strings: | |
$a1 = "minexmr.com" | |
$a2 = "x.opmoner.com" | |
condition: | |
$a1 or $a2 | |
} | |
rule monerocryptopoolfr | |
{ | |
strings: | |
$a1 = "monero.crypto-pool.fr" | |
condition: | |
$a1 | |
} | |
rule monerobackuppoolcom | |
{ | |
strings: | |
$a1 = "monero.backup-pool.com" | |
condition: | |
$a1 | |
} | |
rule monerohashcom | |
{ | |
strings: | |
$a1 = "monerohash.com" | |
condition: | |
$a1 | |
} | |
rule mropooltobe | |
{ | |
strings: | |
$a1 = "mro.poolto.be" | |
condition: | |
$a1 | |
} | |
rule moneroxminingpoolcom | |
{ | |
strings: | |
$a1 = "monero.xminingpool.com" | |
condition: | |
$a1 | |
} | |
rule xmrprohashnet | |
{ | |
strings: | |
$a1 = "xmr.prohash.net" | |
condition: | |
$a1 | |
} | |
rule dwarfpoolcom | |
{ | |
strings: | |
$a1 = "dwarfpool.com" | |
condition: | |
$a1 | |
} | |
rule xmrcryptopoolsorg | |
{ | |
strings: | |
$a1 = "xmr.crypto-pools.org" | |
condition: | |
$a1 | |
} | |
rule moneronet | |
{ | |
strings: | |
$a1 = "monero.net" | |
condition: | |
$a1 | |
} | |
rule hashinvestnet | |
{ | |
strings: | |
$a1 = "hashinvest.net" | |
condition: | |
$a1 | |
} | |
rule stratum_tcp_general | |
{ | |
strings: | |
$a1 = "stratum+tcp" | |
$a2 = "stratum+udp" | |
condition: | |
$a1 or $a2 | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment