{"id":6899,"date":"2019-11-24T00:18:12","date_gmt":"2019-11-24T00:18:12","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=6899"},"modified":"2019-11-24T00:22:52","modified_gmt":"2019-11-24T00:22:52","slug":"yara-to-spellcheckem-all","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2019\/11\/24\/yara-to-spellcheckem-all\/","title":{"rendered":"Yara to spellcheck&#8217;em all"},"content":{"rendered":"\n<p>This is a trivial yara rule stub. It picks up binaries with mispeleleleled words. I have started putting it together only yesterday when I noticed that many of popular (and often signed) binaries include lots of these. This suggests the coders are non-native speakers. The more far-fetching scenarios could include automatic checks against APT for popular misspellings to quickly highlight a possible attribution hints or&#8230; a false flag \ud83d\ude42 <\/p>\n\n\n\n<p>Improve at your own risk \ud83d\ude42<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>rule mispel\n{\n    strings:\n        $s1 = \"appling\" ascii wide\n        $s2 = \"runing\" ascii wide\n        $s3 = \"youre\" ascii wide\n        $s4 = \"faild\" ascii wide\n        $s5 = \"suces\" ascii wide\n        $s6 = \"seting\" ascii wide\n        $s7 = \"opend\" ascii wide\n        $s8 = \"seqence\" ascii wide\n\n    condition:\n        (1 of ($s*))\n}\n\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>This is a trivial yara rule stub. It picks up binaries with mispeleleleled words. I have started putting it together only yesterday when I noticed that many of popular (and often signed) binaries include lots of these. This suggests the &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2019\/11\/24\/yara-to-spellcheckem-all\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,60],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6899"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=6899"}],"version-history":[{"count":2,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6899\/revisions"}],"predecessor-version":[{"id":6901,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6899\/revisions\/6901"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=6899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=6899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=6899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}