Commit 34d88a57 by mmorenog

Merge pull request #75 from apolkosnik/patch-1

Update rovnix to replace M$ word quotes with ASCII quotation marks
parents 29ffb307 9b002f17
rule rovnix_downloader rule rovnix_downloader
{ {
meta: meta:
author=”Intel Security” author="Intel Security"
description=”Rovnix downloader with sinkhole checks” description="Rovnix downloader with sinkhole checks"
reference = "https://blogs.mcafee.com/mcafee-labs/rovnix-downloader-sinkhole-time-checks/" reference = "https://blogs.mcafee.com/mcafee-labs/rovnix-downloader-sinkhole-time-checks/"
strings: strings:
$sink1=”control” $sink1= "control"
$sink2 = “sink” $sink2 = "sink"
$sink3 = “hole” $sink3 = "hole"
$sink4= “dynadot” $sink4= "dynadot"
$sink5= “block” $sink5= "block"
$sink6= “malw” $sink6= "malw"
$sink7= “anti” $sink7= "anti"
$sink8= “googl” $sink8= "googl"
$sink9= “hack” $sink9= "hack"
$sink10= “trojan” $sink10= "trojan"
$sink11= “abuse” $sink11= "abuse"
$sink12= “virus” $sink12= "virus"
$sink13= “black” $sink13= "black"
$sink14= “spam” $sink14= "spam"
$boot= “BOOTKIT_DLL.dll” $boot= "BOOTKIT_DLL.dll"
$mz = { 4D 5A } $mz = { 4D 5A }
condition: condition:
$mz in (0..2) and all of ($sink*) and $boot $mz in (0..2) and all of ($sink*) and $boot
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment