Commit 3bbd9c8c by mmorenog Committed by GitHub

Update RAT_PolishBankRAT.yar

parent 36bbd7ed
rule PolishBankRATsrservice_xorloop { rule PolishBankRATsrservice_xorloop {
meta: meta:
author = “Booz Allen Hamilton Dark Labs” author = "Booz Allen Hamilton Dark Labs"
description = “Finds the custom xor decode loop for <PolishBankRAT-srservice>” description = “Finds the custom xor decode loop for <PolishBankRAT-srservice>”
strings: strings:
...@@ -25,7 +25,7 @@ condition: ...@@ -25,7 +25,7 @@ condition:
rule PolishBankRATfdsvc_decode2 { rule PolishBankRATfdsvc_decode2 {
meta: meta:
author = “Booz Allen Hamilton Dark Labs” author = "Booz Allen Hamilton Dark Labs"
description = “Find a constant used as part of a payload decoding function in PolishBankRAT-fdsvc” description = “Find a constant used as part of a payload decoding function in PolishBankRAT-fdsvc”
strings: strings:
...@@ -45,8 +45,8 @@ condition: ...@@ -45,8 +45,8 @@ condition:
rule decoded_PolishBankRATfdsvc_strings { rule decoded_PolishBankRATfdsvc_strings {
meta: meta:
author = “Booz Allen Hamilton Dark Labs” author = "Booz Allen Hamilton Dark Labs"
description = “Finds hard coded strings in PolishBankRAT-fdsvc” description = "Finds hard coded strings in PolishBankRAT-fdsvc"
strings: strings:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment