diff --git a/malware/Operation_Blockbuster/SierraCharlie.yara b/malware/Operation_Blockbuster/SierraCharlie.yara index 7316f9b..ad07f0c 100644 --- a/malware/Operation_Blockbuster/SierraCharlie.yara +++ b/malware/Operation_Blockbuster/SierraCharlie.yara @@ -18,15 +18,7 @@ rule SierraCharlie FF D1 call ecx ; DnsFree */ - $dnsResolve = { - 8B 0D 50 A7 56 00 - 81 F6 8C 3F 7C 5E - 6A 01 - 50 - 85 C9 - 74 3A - FF D1 - } + $dnsResolve = { 8B 0D 50 A7 56 00 81 F6 8C 3F 7C 5E 6A 01 50 85 C9 74 3A FF D1 } $file1 = "wmplog21t.sqm" $file2 = "wmplog15r.sqm"