Skip to content

Commit f37f758

Browse files
octo-sts[bot]github-actions[bot]stevebeattie
authored
Update third-party rules as of 2025-11-21 (#1227)
Co-authored-by: Update third-party rules <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Steve Beattie <[email protected]>
1 parent 4a68737 commit f37f758

File tree

2 files changed

+8
-8
lines changed

2 files changed

+8
-8
lines changed

third_party/yara/bartblaze/APT/Autumn_Backdoor_Loader.yar

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ rule Autumn_Backdoor_Loader
55
fingerprint = "v1_sha256_09a399531a2e2f8064b1c9862949fa1c9eca1ddab19bfb62a5ce947e002445cc"
66
version = "1.0"
77
date = "2025-11-18"
8-
modified = "2025-11-18"
8+
modified = "2025-11-20"
99
status = "RELEASED"
1010
sharing = "TLP:CLEAR"
1111
source = "BARTBLAZE"
@@ -14,14 +14,14 @@ rule Autumn_Backdoor_Loader
1414
category = "MALWARE"
1515
malware = "UNKNOWN"
1616
malware_type = "BACKDOOR"
17-
reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.broomstick"
17+
reference = "https://cyberarmor.tech/blog/autumn-dragon-china-nexus-apt-group-targets-south-east-asia"
1818
hash = "843fca1cf30c74edd96e7320576db5a39ebf8d0a708bde8ccfb7c12e45a7938c"
1919
hash = "d7711333c34a27aed5d38755f30d14591c147680e2b05eaa0484c958ddaae3b6"
2020

21-
strings:
22-
$pdb_dev = "\\Dev\\ApplicationDllHijacking\\"
23-
$pdb_user = "\\Users\\LG02\\Desktop\\???\\"
21+
strings:
22+
$pdb_dev = "\\Dev\\ApplicationDllHijacking\\"
23+
$pdb_user = "\\Users\\LG02\\Desktop\\???\\"
2424
25-
condition:
26-
any of them
25+
condition:
26+
any of them
2727
}

third_party/yara/bartblaze/RELEASE

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
cce2b61fa7f71aca33a207d52b4d4c84028754fb
1+
1eb421e2de322161c9930a415ec8fa340dbeaf68

0 commit comments

Comments
 (0)