Update codoso-pgv-malware-hash.yaml

patch-4
pussycat0x 2024-06-20 15:33:32 +05:30 committed by GitHub
parent 0c5631b963
commit 687b9c6e63
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 3 additions and 3 deletions

View File

@ -4,8 +4,8 @@ info:
author: pussycat0x
severity: info
description: |
Detects Codoso APT PGV_PVID Malware
reference:
Detects Codoso APT PGV_PVID Malware.
reference:
- https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks
- https://github.com/Yara-Rules/rules/blob/master/malware/APT_Codoso.yar
tags: malware,apt,codoso
@ -21,4 +21,4 @@ file:
- "sha256(raw) == '13bce64b3b5bdfd24dc6f786b5bee08082ea736be6536ef54f9c908fd1d00f75'"
- "sha256(raw) == 'bc0b885cddf80755c67072c8b5961f7f0adcaeb67a1a5c6b3475614fd51696fe'"
- "sha256(raw) == '4b16f6e8414d4192d0286b273b254fa1bd633f5d3d07ceebd03dfdfc32d0f17f'"
condition: or
condition: or