From 2bfa5b61a9a2c855033c5c164b1b1b5c52a48db4 Mon Sep 17 00:00:00 2001 From: jovimon <jovimon@gmail.com> Date: Sat, 2 Jun 2018 19:19:58 +0200 Subject: [PATCH] Update MALW_Mirai_Satori_ELF.yar --- malware/MALW_Mirai_Satori_ELF.yar | 22 ---------------------- 1 file changed, 22 deletions(-) diff --git a/malware/MALW_Mirai_Satori_ELF.yar b/malware/MALW_Mirai_Satori_ELF.yar index b5714bd..443e248 100644 --- a/malware/MALW_Mirai_Satori_ELF.yar +++ b/malware/MALW_Mirai_Satori_ELF.yar @@ -3,28 +3,6 @@ and open to any user or organization, as long as you use it under this license. */ -private rule is__Mirai_gen7 { - meta: - description = "Generic detection for MiraiX version 7" - reference = "http://blog.malwaremustdie.org/2016/08/mmd-0056-2016-linuxmirai-just.html" - author = "unixfreaxjp" - org = "MalwareMustDie" - date = "2018-01-05" - - strings: - $st01 = "/bin/busybox rm" fullword nocase wide ascii - $st02 = "/bin/busybox echo" fullword nocase wide ascii - $st03 = "/bin/busybox wget" fullword nocase wide ascii - $st04 = "/bin/busybox tftp" fullword nocase wide ascii - $st05 = "/bin/busybox cp" fullword nocase wide ascii - $st06 = "/bin/busybox chmod" fullword nocase wide ascii - $st07 = "/bin/busybox cat" fullword nocase wide ascii - - condition: - 5 of them -} - - private rule is__Mirai_Satori_gen { meta: description = "Detects Mirai Satori_gen" -- libgit2 0.26.0