Commit 04c8297f by mmorenog Committed by GitHub

Update APT_Carbanak.yar

parent 37cd8e2e
...@@ -11,7 +11,7 @@ ...@@ -11,7 +11,7 @@
/* Rule Set ----------------------------------------------------------------- */ /* Rule Set ----------------------------------------------------------------- */
rule Carbanak_0915_1 { rule Carbanak_0915_1 : APT {
meta: meta:
description = "Carbanak Malware" description = "Carbanak Malware"
author = "Florian Roth" author = "Florian Roth"
...@@ -25,7 +25,7 @@ rule Carbanak_0915_1 { ...@@ -25,7 +25,7 @@ rule Carbanak_0915_1 {
uint16(0) == 0x5a4d and filesize < 100KB and 1 of them uint16(0) == 0x5a4d and filesize < 100KB and 1 of them
} }
rule Carbanak_0915_2 { rule Carbanak_0915_2 : APT {
meta: meta:
description = "Carbanak Malware" description = "Carbanak Malware"
author = "Florian Roth" author = "Florian Roth"
...@@ -46,7 +46,7 @@ rule Carbanak_0915_2 { ...@@ -46,7 +46,7 @@ rule Carbanak_0915_2 {
uint16(0) == 0x5a4d and filesize < 500KB and ( $x1 or all of ($s*) ) uint16(0) == 0x5a4d and filesize < 500KB and ( $x1 or all of ($s*) )
} }
rule Carbanak_0915_3 { rule Carbanak_0915_3 : APT {
meta: meta:
description = "Carbanak Malware" description = "Carbanak Malware"
author = "Florian Roth" author = "Florian Roth"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment