GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sat Apr 22, 2023 7:59 pm |
|
 |
 |
 |
 |
Some hdb signatures are below for EvilExtractor malware targeting European & North American computers for sensitive information. Although marketed as a legitimate tool, It is sold by a company named Kodex for $59/month, featuring seven attack modules, including ransomware, credential extraction, and Windows Defender bypassing. Doesn’t sound legit to me!
Copy mdb signatures to a new Notepad or similar text writer file and save it in the ClamWin database folder as a file named Sigfile.mdb with a file type of “All Files”. Do not save the file as a text file. The file name should be Sigfile.mdb and nothing else. Anything else will result in a scan error.
Copy hdb signatures to a new Notepad or similar text writer file and save it in the ClamWin database folder as a file named Sigfile.hdb with a file type of “All Files”. Do not save the file as a text file. The file name should be Sigfile.hdb and nothing else. Anything else will result in a scan error.
For multiple signatures, put each signature on a separate line in a Notepad or similar file. Put mdb and hdb signatures in separate files. You can add multiple signatures to the top of an existing mdb or hdb signature file. Copy the signatures, add one blank line to the top of the file and paste the copied signatures there—any additional lines needed will be added. Do not add signatures to the bottom of existing hdb and mdb signature files or you will get a ClamWin scanning error. Delete any blank lines between signatures in a file before saving the file.
After you save a signature file (.hdb, .mdb or .yar) in the ClamWin database folder, scan a file with ClamWin to make sure the signatures work. If you get a scan error, accept my apology, and delete the signature file from the database folder or delete those signatures that you just posted to an existing mdb or hdb file and re-save it after first removing any blank lines in the signature file to make sure all is okay. If you have multiple signature files, run a scan after you save each file to help you locate a file that could cause a scan error.
After 4 weeks, the malware will probably be updated, so you can delete mdb and hdb signatures then. The date (USA) and time (24 hr) are the last two items in each mdb and hdb signature. Yara signatures can be kept permanently if they are not for a specific malware—keep specific sigs for two months.
Thanks to Fortinet via Bleeping Computer!
HDB Signatures
1afb46290a59305692953cc04cdf6749:8486091:Win.Trojan.EvilExtractor-042223.1415
9650ac3a9de8d51fddab092c7956bdae:32205876:Win.Trojan.EvilExtractor-042223.1426
fb970c4367609860c2e5b17737a9f460:11414873:Win.Trojan.EvilExtractor-042223.1434
|
|