Skip to content

Instantly share code, notes, and snippets.

@micahsnyder
Created March 10, 2020 17:08
Show Gist options
  • Save micahsnyder/2449206571b457d83b34c0faa802e5e1 to your computer and use it in GitHub Desktop.
Save micahsnyder/2449206571b457d83b34c0faa802e5e1 to your computer and use it in GitHub Desktop.
example sigtool search
~\workspace\clamav-devel\win32\Win32\Debug [pr/387 ≡]> .\sigtool.exe --find-sigs=".*[mM]aze.*"
[daily.ldb] Win.Malware.Maze-6998740-0;Engine:51-255,Target:1;0&1;556333326e627370616365633937633938633939633130306331303163313032633130336331303463313035633130366331303763313038633130396331313063;727573717375753d
[daily.ldb] Win.Ransomware.Maze-7449729-0;Engine:51-255,Target:1;(0|1);566A40680030000068E1C505006A00FF15;C1C009C1C90A33C88B8610100000C1C80803C8014CBE38
[daily.ldb] Win.Ransomware.Maze-7473718-0;Engine:51-255,Target:1;(0|1|2|3|4|5);62696e5c6361636f6665762e706462;433a5c64656d6f6e736c61793333355c656d7369736f66745f776f726b5c72616e736f6d776172655c6875746368696e732e706462;633a5c6e6561725c766572795c677265775c50656f706c6542656c696576652e706462;433a5c72616e646f6d5c6675636b696e675c706174685c746f5c6675636b696e675c6964696f7469635c6e6f6e6578697374696e675c66696c655c776974685c7064625c657874656e73696f6e2e706462;433a5c736869745c6761766e6f2e706462;433a5c7a656c6f33355f6669786f6d656b61666579755c62696d75647570616c696a5f7369736564697a65736f6c6f76692e706462
[daily.ndb] Win.Trojan.Maze-1:0:*:0e1f8bf583ee??bf0501f3a406b82135cd211f891e????8c06??????????b821252ec606????00cd211fba0800b8????cd21588ed88ec0817e004d5a7407817e005a4d75
[daily.ndb] Win.Ransomware.Maze-7473719-0:1:*:35fab200002d86480000c745??b6c700002db3eb000081f0a8e90000
[daily.ndb] Win.Ransomware.Maze-7473720-0:1:*:b80100000069c810f60200034d??894d??8b55??81ea10f602008955??c745??000000008d45
[daily.ndb] Win.Ransomware.Maze-7473721-0:1:*:0345??0145??f745??413c00002945??be6a59000081e76551000081f2c9a9000005e77e00002d2ecd00002d18220000
[daily.ndb] Win.Ransomware.Maze-7473723-0:1:*:c745??ba78000005e1a9000089bb18384000488145??aef600003589d7000081e2b89e0000ff4d??ff45??ff4d??8375??004e
[daily.ndb] Win.Ransomware.Maze-7473751-0:1:*:050739000083f200ff8b88354000ff4d??3500000000be00000000816d??98aa0000bf745c000081c1774a000081e188fb0000058f5a000041
[daily.ndb] Win.Ransomware.Maze-7473752-0:1:*:816d??00e7000023fa8955??81e1bb5a000025b158000081f6ec5d000025dc570000314d??854d??bf9f44000023c983f20035e92d0000
[daily.ndb] Win.Ransomware.Maze-7473753-0:1:*:81c6000200003344b1188b4d??8941188b45??8b806c10000088c28895{4}8b45??8b806c100000c1e81088c28895{4}8b45??0fb68d{4}8b04888b4d??0fb6b5{4}81c600010000
[daily.ndb] Win.Ransomware.Maze-7473759-0:1:*:81cead380000ba4123000035e9c500008555??4085caff8bb0324000ff4d??834d??008165??330f00002b83ac3240008175??77870000ba2b3b0000
[daily.ndb] Win.Ransomware.Maze-7473772-0:1:*:b9040000006bd10f8b45??8b4d??8b75??8b4c8e3c898c10001000008b55??8b45??8b8d{4}334c903c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment