Neo23x0 / Loki

Loki - Simple IOC and YARA Scanner
https://www.nextron-systems.com/compare-our-scanners/
GNU General Public License v3.0
3.38k stars 580 forks source link

a bunch of "unreferenced string" and "invalid field name" errors when running loki.py #147

Closed li-xin-yi closed 4 years ago

li-xin-yi commented 4 years ago

I used a brand new Ubuntu 16.04 VM from osboxes and hosted it in VirtualBox. I cloned the whole repo and installed all dependencies (including built-in python 2.7 in Ubuntu). Then when I first typed:

python loki.py

Even though it prompted the welcome page and started to scan, It gave plenty of error messages:

image

I copy and paste all logs now:

[NOTICE] Starting Loki Scan VERSION: 0.30.7 SYSTEM: osboxes TIME: 20200609T02:54:45Z PLATFORM:     PROC: x86_64 ARCH: 64bit ELF
[NOTICE] Registered plugin PluginWMI
[NOTICE] Loaded plugin /home/osboxes/Downloads/Loki/plugins/loki-plugin-wmi.py
[NOTICE] PE-Sieve successfully initialized BINARY: /home/osboxes/Downloads/Loki/tools/pe-sieve64.exe SOURCE: https://github.com/hasherezade/pe-sieve
[INFO] File Name Characteristics initialized with 2832 regex patterns
[INFO] C2 server indicators initialized with 1541 elements
[INFO] Malicious MD5 Hashes initialized with 19025 hashes
[INFO] Malicious SHA1 Hashes initialized with 7100 hashes
[INFO] Malicious SHA256 Hashes initialized with 22779 hashes
[INFO] False Positive Hashes initialized with 30 hashes
[INFO] Processing YARA rules folder /home/osboxes/Downloads/Loki/signature-base/yara
[ERROR] Error while initializing Yara rule apt_apt10_redleaves.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt10_redleaves.yar(43): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt10_redleaves.yar(43): invalid field name "imphash"
[ERROR] Error while initializing Yara rule gen_sign_anomalies.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/gen_sign_anomalies.yar(24): invalid field name "number_of_signatures"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/gen_sign_anomalies.yar(24): invalid field name "number_of_signatures"
[ERROR] Error while initializing Yara rule apt_sofacy.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_sofacy.yar(71): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_sofacy.yar(71): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_op_honeybee.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_op_honeybee.yar(83): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_op_honeybee.yar(83): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_tick_weaponized_usb.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tick_weaponized_usb.yar(56): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tick_weaponized_usb.yar(56): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule thor-hacktools.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/thor-hacktools.yar(4571): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/thor-hacktools.yar(4571): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_babyshark.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_babyshark.yar(49): undefined string "$a1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_babyshark.yar(49): undefined string "$a1"
[ERROR] Error while initializing Yara rule apt_khrat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_khrat.yar(58): undefined string "$x*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_khrat.yar(58): undefined string "$x*"
[ERROR] Error while initializing Yara rule apt_cmstar.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_cmstar.yar(26): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_cmstar.yar(26): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_nansh0u.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_nansh0u.yar(129): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_nansh0u.yar(129): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_freemilk.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_freemilk.yar(100): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_freemilk.yar(100): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule crime_ryuk_ransomware.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_ryuk_ransomware.yar(19): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_ryuk_ransomware.yar(19): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_winnti.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_winnti.yar(355): undefined string "$*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_winnti.yar(355): undefined string "$*"
[ERROR] Error while initializing Yara rule apt_apt10.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt10.yar(1395): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt10.yar(1395): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_tick_datper.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tick_datper.yar(38): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tick_datper.yar(38): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_silence.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_silence.yar(58): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_silence.yar(58): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_cobaltgang.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_cobaltgang.yar(87): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_cobaltgang.yar(87): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_turla_gazer.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla_gazer.yar(50): undefined string "$*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla_gazer.yar(50): undefined string "$*"
[ERROR] Error while initializing Yara rule apt_golddragon.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_golddragon.yar(147): undefined string "$*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_golddragon.yar(147): undefined string "$*"
[ERROR] Error while initializing Yara rule apt_apt41.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt41.yar(255): undefined string "$x*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt41.yar(255): undefined string "$x*"
[ERROR] Error while initializing Yara rule crime_atm_dispenserxfs.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_atm_dispenserxfs.yar(20): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_atm_dispenserxfs.yar(20): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_greyenergy.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_greyenergy.yar(92): unreferenced string "$s12"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_greyenergy.yar(92): unreferenced string "$s12"
[ERROR] Error while initializing Yara rule apt_lotusblossom_elise.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lotusblossom_elise.yar(28): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lotusblossom_elise.yar(28): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_exile_rat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_exile_rat.yar(22): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_exile_rat.yar(22): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_trickbot.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_trickbot.yar(108): undefined string "$x*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_trickbot.yar(108): undefined string "$x*"
[ERROR] Error while initializing Yara rule gen_google_anomaly.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/gen_google_anomaly.yar(20): invalid field name "number_of_signatures"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/gen_google_anomaly.yar(20): invalid field name "number_of_signatures"
[ERROR] Error while initializing Yara rule crime_mal_nitol.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_nitol.yar(25): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_nitol.yar(25): invalid field name "imphash"
[ERROR] Error while initializing Yara rule gen_loaders.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/gen_loaders.yar(159): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/gen_loaders.yar(159): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_sofacy_oct17_camp.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_sofacy_oct17_camp.yar(65): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_sofacy_oct17_camp.yar(65): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_snarasite.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_snarasite.yar(13): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_snarasite.yar(13): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_oilrig_oct17.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig_oct17.yar(107): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig_oct17.yar(107): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_ta17_318B.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_318B.yar(68): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_318B.yar(68): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_monsoon.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_monsoon.yar(60): undefined string "$x*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_monsoon.yar(60): undefined string "$x*"
[ERROR] Error while initializing Yara rule apt_zxshell.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_zxshell.yar(127): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_zxshell.yar(127): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_ta17_318A.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_318A.yar(90): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_318A.yar(90): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_lazarus_jun18.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lazarus_jun18.yar(80): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lazarus_jun18.yar(80): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule apt_darkhydrus.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_darkhydrus.yar(100): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_darkhydrus.yar(100): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_ta18_149A.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta18_149A.yar(72): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta18_149A.yar(72): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_mal_grandcrab.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_grandcrab.yar(12): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_grandcrab.yar(12): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_apt12_malware.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt12_malware.yar(23): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt12_malware.yar(23): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_oilrig_rgdoor.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig_rgdoor.yar(34): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig_rgdoor.yar(34): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_thrip.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_thrip.yar(348): undefined string "$*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_thrip.yar(348): undefined string "$*"
[ERROR] Error while initializing Yara rule gen_pupy_rat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/gen_pupy_rat.yar(42): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/gen_pupy_rat.yar(42): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_oilrig.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig.yar(312): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_oilrig.yar(312): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_keyboys.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_keyboys.yar(150): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_keyboys.yar(150): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_greenbug.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_greenbug.yar(157): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_greenbug.yar(157): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_reaver_sunorcal.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_reaver_sunorcal.yar(99): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_reaver_sunorcal.yar(99): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_turla_mosquito.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla_mosquito.yar(137): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla_mosquito.yar(137): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_lazarus_applejeus.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lazarus_applejeus.yar(96): unreferenced string "$cod0"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_lazarus_applejeus.yar(96): unreferenced string "$cod0"
[ERROR] Error while initializing Yara rule apt_olympic_destroyer.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_olympic_destroyer.yar(52): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_olympic_destroyer.yar(52): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_floxif_flystudio.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_floxif_flystudio.yar(33): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_floxif_flystudio.yar(33): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_shadowpad.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_shadowpad.yar(30): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_shadowpad.yar(30): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_agent_btz.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_agent_btz.yar(98): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_agent_btz.yar(98): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_dragonfly.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_dragonfly.yar(103): undefined string "$*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_dragonfly.yar(103): undefined string "$*"
[ERROR] Error while initializing Yara rule apt_ta17_293A.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_293A.yar(218): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_ta17_293A.yar(218): invalid field name "imphash"
[ERROR] Error while initializing Yara rule mal_cryp_rat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/mal_cryp_rat.yar(15): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/mal_cryp_rat.yar(15): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_mal_ransom_wadharma.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_ransom_wadharma.yar(11): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_mal_ransom_wadharma.yar(11): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_middle_east_talosreport.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_middle_east_talosreport.yar(95): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_middle_east_talosreport.yar(95): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_cn_campaign_njrat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_cn_campaign_njrat.yar(153): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_cn_campaign_njrat.yar(153): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule apt_suckfly.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_suckfly.yar(81): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_suckfly.yar(81): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_microcin.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_microcin.yar(122): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_microcin.yar(122): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule gen_xtreme_rat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/gen_xtreme_rat.yar(78): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/gen_xtreme_rat.yar(78): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_bigbang.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_bigbang.yar(49): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_bigbang.yar(49): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule apt_apt17_mal_sep17.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt17_mal_sep17.yar(98): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_apt17_mal_sep17.yar(98): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_donotteam_ytyframework.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_donotteam_ytyframework.yar(39): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_donotteam_ytyframework.yar(39): invalid field name "imphash"
[ERROR] Error while initializing Yara rule crime_kasper_oct17.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_kasper_oct17.yar(26): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_kasper_oct17.yar(26): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_slingshot.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_slingshot.yar(135): undefined string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_slingshot.yar(135): undefined string "$x1"
[ERROR] Error while initializing Yara rule apt_tophat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tophat.yar(74): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_tophat.yar(74): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule apt_winnti_burning_umbrella.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_winnti_burning_umbrella.yar(436): unreferenced string "$s2"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_winnti_burning_umbrella.yar(436): unreferenced string "$s2"
[ERROR] Error while initializing Yara rule crime_emotet.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/crime_emotet.yar(32): invalid field name "imphash"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/crime_emotet.yar(32): invalid field name "imphash"
[ERROR] Error while initializing Yara rule apt_rokrat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_rokrat.yar(121): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_rokrat.yar(121): unreferenced string "$s1"
[ERROR] Error while initializing Yara rule apt_bronze_butler.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_bronze_butler.yar(188): undefined string "$x*"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_bronze_butler.yar(188): undefined string "$x*"
[ERROR] Error while initializing Yara rule apt_rehashed_rat.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_rehashed_rat.yar(81): unreferenced string "$x1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_rehashed_rat.yar(81): unreferenced string "$x1"
[ERROR] Error while initializing Yara rule apt_turla.yar ERROR: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla.yar(261): unreferenced string "$s1"
Traceback (most recent call last):
  File "loki.py", line 1088, in initialize_yara_rules
    'md5': dummy,
SyntaxError: /home/osboxes/Downloads/Loki/signature-base/yara/apt_turla.yar(261): unreferenced string "$s1"
[INFO] Initializing all YARA rules at once (composed string of all rule files)
[INFO] Initialized 399 Yara rules
[INFO] Reading private rules from binary ...
[NOTICE] Program should be run as 'root' to ensure all access rights to process memory and file objects.
[NOTICE] Running plugin PluginWMI
[NOTICE] Finished running plugin PluginWMI
[INFO] Scanning / ...  
[INFO] Skipping /sys directory
[INFO] Skipping /media directory
[INFO] Skipping /dev directory
[INFO] Skipping /run directory
[INFO] Skipping /proc directory
Neo23x0 commented 4 years ago

Please provide the output of

yara --version

and

pip list | grep yara

Your YARA hasn't been built with OpenSSL present. You could try to uninstall yara-python, install openssl with

sudo apt-get install libssl-dev

then reinstall yara-python.

li-xin-yi commented 4 years ago
$ yara --version
yara 3.4.0
$ pip list | grep yara
yara-python (4.0.1)

I did

$  pip uninstall yara-python
$  sudo apt remove yara
$  sudo apt-get install libssl-dev
$  pip install yara-python

But it still gave the same errors.

li-xin-yi commented 4 years ago

Please provide the output of

yara --version

and

pip list | grep yara

Your YARA hasn't been built with OpenSSL present. You could try to uninstall yara-python, install openssl with

sudo apt-get install libssl-dev

then reinstall yara-python.

Fixed.

Somehow, I su as root user and build yara according to this documentation then pip install all dependencies again. It works. Even if I log-in as a normal user, I can still run loki without errors now.

Thanks.