Unverified Commit 2bfa5b61 by jovimon Committed by GitHub

Update MALW_Mirai_Satori_ELF.yar

parent 367950a3
...@@ -3,28 +3,6 @@ ...@@ -3,28 +3,6 @@
and open to any user or organization, as long as you use it under this license. and open to any user or organization, as long as you use it under this license.
*/ */
private rule is__Mirai_gen7 {
meta:
description = "Generic detection for MiraiX version 7"
reference = "http://blog.malwaremustdie.org/2016/08/mmd-0056-2016-linuxmirai-just.html"
author = "unixfreaxjp"
org = "MalwareMustDie"
date = "2018-01-05"
strings:
$st01 = "/bin/busybox rm" fullword nocase wide ascii
$st02 = "/bin/busybox echo" fullword nocase wide ascii
$st03 = "/bin/busybox wget" fullword nocase wide ascii
$st04 = "/bin/busybox tftp" fullword nocase wide ascii
$st05 = "/bin/busybox cp" fullword nocase wide ascii
$st06 = "/bin/busybox chmod" fullword nocase wide ascii
$st07 = "/bin/busybox cat" fullword nocase wide ascii
condition:
5 of them
}
private rule is__Mirai_Satori_gen { private rule is__Mirai_Satori_gen {
meta: meta:
description = "Detects Mirai Satori_gen" description = "Detects Mirai Satori_gen"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment