Commit 43ebf112 by mmorenog

Update SierraCharlie.yara

parent b5c2bd95
......@@ -18,15 +18,7 @@ rule SierraCharlie
FF D1 call ecx ; DnsFree
*/
$dnsResolve = {
8B 0D 50 A7 56 00
81 F6 8C 3F 7C 5E
6A 01
50
85 C9
74 3A
FF D1
}
$dnsResolve = { 8B 0D 50 A7 56 00 81 F6 8C 3F 7C 5E 6A 01 50 85 C9 74 3A FF D1 }
$file1 = "wmplog21t.sqm"
$file2 = "wmplog15r.sqm"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment