Unverified Commit 1ad69954 by jovimon Committed by GitHub

Move is__elf to MISC_Utils.yar

parent 8fcbb5e5
......@@ -24,18 +24,6 @@ private rule is__Mirai_gen7 {
5 of them
}
private rule is__elf {
meta:
author = "@mmorenog,@yararules"
strings:
$header = { 7F 45 4C 46 }
condition:
$header at 0
}
rule Mirai_Okiru {
meta:
description = "Detects Mirai Okiru MALW"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment