Commit 1aa98908 by mmorenog

Update Equation.yar

parent 8cadff08
...@@ -571,6 +571,7 @@ rule EquationDrug_FileSystem_Filter { ...@@ -571,6 +571,7 @@ rule EquationDrug_FileSystem_Filter {
rule apt_equation_keyword { rule apt_equation_keyword {
meta: meta:
description = "Rule to detect Equation group's keyword in executable file" description = "Rule to detect Equation group's keyword in executable file"
author = "Florian Roth @4nc4p"
last_modified = "2015-09-26" last_modified = "2015-09-26"
reference = "http://securelist.com/blog/research/68750/equation-the-death-star-of-malware-galaxy/" reference = "http://securelist.com/blog/research/68750/equation-the-death-star-of-malware-galaxy/"
strings: strings:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment