Commit 3bbd9c8c by mmorenog Committed by GitHub

Update RAT_PolishBankRAT.yar

parent 36bbd7ed
rule PolishBankRATsrservice_xorloop {
meta:
author = “Booz Allen Hamilton Dark Labs”
author = "Booz Allen Hamilton Dark Labs"
description = “Finds the custom xor decode loop for <PolishBankRAT-srservice>”
strings:
......@@ -25,7 +25,7 @@ condition:
rule PolishBankRATfdsvc_decode2 {
meta:
author = “Booz Allen Hamilton Dark Labs”
author = "Booz Allen Hamilton Dark Labs"
description = “Find a constant used as part of a payload decoding function in PolishBankRAT-fdsvc”
strings:
......@@ -45,8 +45,8 @@ condition:
rule decoded_PolishBankRATfdsvc_strings {
meta:
author = “Booz Allen Hamilton Dark Labs”
description = “Finds hard coded strings in PolishBankRAT-fdsvc”
author = "Booz Allen Hamilton Dark Labs"
description = "Finds hard coded strings in PolishBankRAT-fdsvc"
strings:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment