ANY.RUN monthly updates: New Config Extractors, Suricata Rules, and More
DUBAI, UNITED ARAB EMIRATES, August 31, 2023/EINPresswire.com/ -- ANY.RUN, a cloud interactive sandbox for malware analysis, has released a Monthly Updates: New Config Extractors, Suricata Rules, and More.
๐๐ซ๐จ๐๐ฎ๐๐ญ ๐ฎ๐ฉ๐๐๐ญ๐๐ฌ
New detection logic for IP, URL, Domain. The overhauled logic enables more robust detection of malicious IPs, URLs, and domains.
๐๐๐ฐ ๐ฆ๐๐ฅ๐ฐ๐๐ซ๐ ๐๐จ๐ง๐๐ข๐ ๐๐ฑ๐ญ๐ซ๐๐๐ญ๐จ๐ซ๐ฌ ๐๐ง๐ ๐๐ข๐ฑ๐๐ฌ
ANY.RUNโs added support for several new malware and improved detection capabilities for families that were already supported: Lu0Bot support, Strela extractor and new YARA rules, RaccoonClipper extractor and new YARA rules, Fixed extractor and rules for LummaStealer.
๐๐๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐ฎ๐ฉ๐๐๐ญ๐๐ฌ
โข Added a rule to detect KrakenStealer
โข Updated extractor and YARA for GO LaplasClipper variations
โข Updated RaccoonStealer extractor and YARA
โข Updated extractor and YARA for StealC
โข Updated Remcos extractor and YARA
โข Separated tags between StormKitty and AsyncRAT
โข Added support for extracting configuration from new XWorm types.
๐๐๐ญ๐ฐ๐จ๐ซ๐ค ๐ซ๐ฎ๐ฅ๐๐ฌ
In August, ANY.RUN focused on network rules heavily, writing 120 new Suricata rules.
๐๐จ๐ง๐ญ๐ซ๐ข๐๐ฎ๐ญ๐ข๐ง๐ ๐ญ๐จ ๐๐ฆ๐๐ซ๐ ๐ข๐ง๐ ๐๐ก๐ซ๐๐๐ญ๐ฌ ๐๐จ๐ฆ๐ฆ๐ฎ๐ง๐ข๐ญ๐ฒ
This month, ANY.RUN continued submitting rules to the Emerging Threats community:
โข Parallax RAT now detectable
โข Mekotio rules boosted
โข New rule for DarkCloud stealer.
The ANY.RUN team works hard to keep up with emerging threats.
Read more with examples in the article at ANY.RUN.
Vlada Belousova
ANYRUN FZCO
2027889264
email us here
Visit us on social media:
Twitter
YouTube
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
