Commit 4c886a76 by Marc Rivero López Committed by GitHub

Update EXPERIMENTAL_Beef.yar

parent 89db04c6
......@@ -10,12 +10,14 @@
*/
rule BeEF_browser_hooked : experimental {
rule BeEF_browser_hooked : experimental
{
meta:
description = "Yara rule related to hook.js, BeEF Browser hooking capability"
author = "Pasquale Stirparo"
date = "2015-10-07"
hash1 = "587e611f49baf63097ad2421ad0299b7b8403169ec22456fb6286abf051228db"
strings:
$s0 = "mitb.poisonAnchor" wide ascii
$s1 = "this.request(this.httpproto" wide ascii
......@@ -36,6 +38,7 @@ rule BeEF_browser_hooked : experimental {
$s16 = "uagent.search(engineOpera)" wide ascii
$s17 = "mitb.sniff" wide ascii
$s18 = "beef.logger.start" wide ascii
condition:
all of them
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment