/* Deep Panda APT */ rule DeepPanda_sl_txt_packed { meta: description = "Hack Deep Panda - ScanLine sl-txt-packed" license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE" author = "Florian Roth (Nextron Systems)" date = "2015/02/08" hash = "ffb1d8ea3039d3d5eb7196d27f5450cac0ea4f34" id = "7a335810-2bf9-5a0b-bef4-1bade65a0f00" strings: $s0 = "Command line port scanner" fullword wide $s1 = "sl.exe" fullword wide $s2 = "CPports.txt" fullword ascii $s3 = ",GET / HTTP/.}" fullword ascii $s4 = "Foundstone Inc." fullword wide $s9 = " 2002 Foundstone Inc." fullword wide $s15 = ", Inc. 2002" fullword ascii $s20 = "ICMP Time" fullword ascii condition: all of them } rule DeepPanda_lot1 { meta: description = "Hack Deep Panda - lot1.tmp-pwdump" license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE" author = "Florian Roth (Nextron Systems)" date = "2015/02/08" hash = "5d201a0fb0f4a96cefc5f73effb61acff9c818e1" id = "c72120a5-8637-580c-9856-e070dfb6df94" strings: $s0 = "Unable to open target process: %d, pid %d" fullword ascii $s1 = "Couldn't delete target executable from remote machine: %d" fullword ascii $s2 = "Target: Failed to load SAM functions." fullword ascii $s5 = "Error writing the test file %s, skipping this share" fullword ascii $s6 = "Failed to create service (%s/%s), error %d" fullword ascii $s8 = "Service start failed: %d (%s/%s)" fullword ascii $s12 = "PwDump.exe" fullword ascii $s13 = "GetAvailableWriteableShare returned an error of %ld" fullword ascii $s14 = ":\\\\.\\pipe\\%s" fullword ascii $s15 = "Couldn't copy %s to destination %s. (Error %d)" fullword ascii $s16 = "dump logon session" fullword ascii $s17 = "Timed out waiting to get our pipe back" fullword ascii $s19 = "SetNamedPipeHandleState failed, error %d" fullword ascii $s20 = "%s\\%s.exe" fullword ascii condition: 10 of them } rule DeepPanda_htran_exe { meta: description = "Hack Deep Panda - htran-exe" license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE" author = "Florian Roth (Nextron Systems)" date = "2015/02/08" hash = "38e21f0b87b3052b536408fdf59185f8b3d210b9" id = "2a551e82-aff1-5a77-bc5e-d06e49dca8bc" strings: $s0 = "%s -