Skip to content

Repository files navigation

kirkderp/yara - YARA Rules from derp.ca

YARA rules published alongside research on derp.ca, a malware C2 tracker and threat intelligence project tracking active malware infrastructure.

Rules

Each directory contains a YARA rule and a short public README for the matching malware sample, case, or family.

Rules are scoped to the evidence available at publication time. Some rules target a submitted sample or case-specific chain; others target broader family traits when enough stable code, protocol, or structural evidence is available.

Metadata

Rules follow CCCS validator expectations and include YARAhub-compatible metadata where applicable.

Deployment

Rules are deployed to:

License

All rules in this repository are dedicated to the public domain under CC0 1.0 Universal. No attribution required, but a link back to derp.ca is appreciated.

About derp.ca

derp.ca tracks malware C2 infrastructure and publishes technical malware analysis.

About

YARA Rules from derp.ca adventures

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages