Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
rule elf_loerbas_w0 { meta: author = "Tillmann Werner" description = "detects loader module" source = "https://twitter.com/nunohaien/status/1261281419483140096" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.loerbas" malpedia_version = "20200518" malpedia_license = "CC BY-NC-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $fragemnt = { 61 31 C2 8B 45 FC 48 98 } condition: all of them }
rule elf_loerbas_w1 { meta: author = "Tillmann Werner" description = "detects cleaner module" source = "https://twitter.com/nunohaien/status/1261281419483140096" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/elf.loerbas" malpedia_version = "20200518" malpedia_license = "CC BY-NC-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $fragemnt = { 14 CC FC 28 25 DE B9 } condition: all of them }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY