![]() |
|
#27
|
||||
|
||||
|
make a file called Rsa.yar
remember to add it to the index file Code:
rule Rsa
{
strings:
$a = {30 82 ?? ?? 30 82 ?? ??} // x509 OpenSSL 1024 Cert public key
$b = {30 82 ?? ?? 02 01 00} // pkcs OpenSSL 1024 bit RSA Private Key
condition:
$a or $b
}
Bridge found the public rsa key that way in post 16 http://forum.exetools.com/showpost.p...7&postcount=16 but offcause it could be ofuscated and embedded in other files these days, and very hard to find https://b161268c3bf5a87bc67309e7c870...ARA-Manual.pdf Yara is almost a own script langueg by itself. Last edited by Storm Shadow; 08-09-2014 at 17:42. |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Find the Algorithm | mcr4ck | General Discussion | 3 | 05-26-2020 18:19 |
| Find the Algorithm | mcr4ck | General Discussion | 18 | 02-06-2020 15:43 |