Commit 25f5079b by mmorenog

Update APT_threatgroup_3390.yar

Bugfix
parent de41c72b
...@@ -188,7 +188,7 @@ rule ThreatGroup3390_Strings { ...@@ -188,7 +188,7 @@ rule ThreatGroup3390_Strings {
$s4 = "c:\\temp\\ipcan.exe" fullword ascii $s4 = "c:\\temp\\ipcan.exe" fullword ascii
$s5 = "<%eval(Request.Item(\"admin-na-google123!@#" ascii $s5 = "<%eval(Request.Item(\"admin-na-google123!@#" ascii
condition: condition:
1 of them and filesize 30KB 1 of them and filesize < 30KB
} }
rule ThreatGroup3390_C2 { rule ThreatGroup3390_C2 {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment