Commit 2688c758 by Yara Rules

Modified rule LinuxElknot

Modified rule LinuxElknot
Commit: d39c1bf90d8e2adbbc32f295a2b0d89c4cfd7826
Thank you @Nyx0
parent 3030082a
...@@ -42,15 +42,17 @@ rule LinuxBillGates ...@@ -42,15 +42,17 @@ rule LinuxBillGates
rule LinuxElknot rule LinuxElknot
{ {
meta: meta:
author = "@benkow_" Author = "@benkow_"
description = "http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3099" Date = "2013/12/24"
Description = "Strings inside"
Reference = "http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3099"
strings: strings:
$a = "ZN8CUtility7DeCryptEPciPKci" $a = "ZN8CUtility7DeCryptEPciPKci"
$b = "ZN13CThreadAttack5StartEP11CCmdMessage" $b = "ZN13CThreadAttack5StartEP11CCmdMessage"
condition: condition:
$a and $b all of them
} }
rule LinuxMrBlack rule LinuxMrBlack
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment