Commit 4abed794 by mmorenog

Update Android_malware_SMSsender.yar

parent 88d64657
...@@ -5,7 +5,7 @@ ...@@ -5,7 +5,7 @@
rule smspay_chinnese : hejupay rule smspay_chinnese : hejupay
{ {
meta: meta:
author = "Fernando Denis" author = "Fernando Denis https://twitter.com/fdrg21"
reference = "https://koodous.com/" reference = "https://koodous.com/"
strings: strings:
...@@ -22,7 +22,7 @@ import "androguard" ...@@ -22,7 +22,7 @@ import "androguard"
rule smsfraud : ganga rule smsfraud : ganga
{ {
meta: meta:
author = "Fernando Denis" author = "Fernando Denis https://twitter.com/fdrg21"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "smsfraud chinese" description = "smsfraud chinese"
sample = "e6ef34577a75fc0dc0a1f473304de1fc3a0d7d330bf58448db5f3108ed92741b" sample = "e6ef34577a75fc0dc0a1f473304de1fc3a0d7d330bf58448db5f3108ed92741b"
...@@ -44,7 +44,7 @@ import "androguard" ...@@ -44,7 +44,7 @@ import "androguard"
rule sms_fraud : MSACM32 rule sms_fraud : MSACM32
{ {
meta: meta:
author = "Fernando Denis" author = "Fernando Denis https://twitter.com/fdrg21"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "sms-fraud examples" description = "sms-fraud examples"
sample = "8b9cabd2dafbba57bc35a19b83bf6027d778f3b247e27262ced618e031f9ca3d c52112b45164b37feeb81e0b5c4fcbbed3cfce9a2782a2a5001fb37cfb41e993" sample = "8b9cabd2dafbba57bc35a19b83bf6027d778f3b247e27262ced618e031f9ca3d c52112b45164b37feeb81e0b5c4fcbbed3cfce9a2782a2a5001fb37cfb41e993"
...@@ -63,7 +63,7 @@ rule sms_fraud : MSACM32 ...@@ -63,7 +63,7 @@ rule sms_fraud : MSACM32
rule sms_fraud_gen : generic rule sms_fraud_gen : generic
{ {
meta: meta:
author = "Fernando Denis" author = "Fernando Denis https://twitter.com/fdrg21"
reference = "https://koodous.com/" reference = "https://koodous.com/"
description = "This is just an example" description = "This is just an example"
thread_level = 3 thread_level = 3
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment