Update Yara_Patchwork_July_2020_1.yar
This commit is contained in:
parent
60404a8cf9
commit
1b0de13363
@ -56,8 +56,7 @@ rule Mal_BadNews_2016_OPChina_1 {
|
|||||||
$s13 = "image/jpeg" fullword wide
|
$s13 = "image/jpeg" fullword wide
|
||||||
$s14 = "https://en.wikipnet/search.php" fullword ascii /* legit site used as test for connectivity*/
|
$s14 = "https://en.wikipnet/search.php" fullword ascii /* legit site used as test for connectivity*/
|
||||||
condition:
|
condition:
|
||||||
uint16(0) == 0x5a4d and filesize > 70KB and ( pe.imphash() == "c71a34b50e03311fe548bb5a730e97ac" and ( pe.exports("JLI_AcceptableRelease") and pe.exports("JLI_ExactVersionId") and pe.exports("JLI_FreeManifest") and pe.exports("JLI_JarUnpackFile") and pe.exports("JLI_MemFree") and pe.exports("JLI_MemRealloc") ) and 12 of them
|
uint16(0) == 0x5a4d and filesize > 70KB and ( pe.imphash() == "c71a34b50e03311fe548bb5a730e97ac" and ( pe.exports("JLI_AcceptableRelease") and pe.exports("JLI_ExactVersionId") and pe.exports("JLI_FreeManifest") and pe.exports("JLI_JarUnpackFile") and pe.exports("JLI_MemFree") and pe.exports("JLI_MemRealloc") and 12 of them)
|
||||||
}
|
|
||||||
|
|
||||||
rule Mal_BozokRAT_July2020_2 {
|
rule Mal_BozokRAT_July2020_2 {
|
||||||
meta:
|
meta:
|
||||||
|
Loading…
Reference in New Issue
Block a user