Commit 256601a6 by mmorenog Committed by GitHub

Update RANSOM_Petya.yar

parent e09292fa
...@@ -30,3 +30,16 @@ rule Petya_Ransomware { ...@@ -30,3 +30,16 @@ rule Petya_Ransomware {
condition: condition:
uint16(0) == 0x5a4d and filesize < 500KB and $a1 and 3 of ($s*) uint16(0) == 0x5a4d and filesize < 500KB and $a1 and 3 of ($s*)
} }
rule Ransom.Petya {
meta:
description = "Regla para detectar Ransom.Petya con md5 AF2379CC4D607A45AC44D62135FB7015"
author = "CCN-CERT”"
version = "1.0"
strings:
$ = { C1 C8 14 2B F0 03 F0 2B F0 03 F0 C1 C0 14 03 C2 }
$ = { 46 F7 D8 81 EA 5A 93 F0 12 F7 DF C1 CB 10 81 F6 }
$ = { 0C 88 B9 07 87 C6 C1 C3 01 03 C5 48 81 C3 A3 01 00 00 }
condition:
all of them
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment