Commit 3d0cd31b by Ryan B

add .yar extension to Maldoc_hancitor_dropper and add to index

Signed-off-by: Ryan B <randomrhythm@rhythmengineering.com>
parent 84039586
/*
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
rule hancitor_dropper : vb_win32api rule hancitor_dropper : vb_win32api
{ {
meta: meta:
......
...@@ -11,6 +11,7 @@ include "./maldocs/Maldoc_CVE_2017_8759.yar" ...@@ -11,6 +11,7 @@ include "./maldocs/Maldoc_CVE_2017_8759.yar"
include "./maldocs/Maldoc_Contains_VBE_File.yar" include "./maldocs/Maldoc_Contains_VBE_File.yar"
include "./maldocs/Maldoc_DDE.yar" include "./maldocs/Maldoc_DDE.yar"
include "./maldocs/Maldoc_Dridex.yar" include "./maldocs/Maldoc_Dridex.yar"
include "./maldocs/Maldoc_hancitor_dropper.yar"
include "./maldocs/Maldoc_Hidden_PE_file.yar" include "./maldocs/Maldoc_Hidden_PE_file.yar"
include "./maldocs/Maldoc_MIME_ActiveMime_b64.yar" include "./maldocs/Maldoc_MIME_ActiveMime_b64.yar"
include "./maldocs/Maldoc_PDF.yar" include "./maldocs/Maldoc_PDF.yar"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment