Commit 54987c9a by mmorenog

Update BlackShades.yar

parent 23957f3b
...@@ -116,3 +116,19 @@ rule BlackShades : Trojan ...@@ -116,3 +116,19 @@ rule BlackShades : Trojan
$signature1 and $signature2 and $signature3 $signature1 and $signature2 and $signature3
} }
rule BlackShades_25052015
{
meta:
author = "Brian Wallace (@botnet_hunter)"
date = "2014/04"
ref = "http://malwareconfig.com/stats/PoisonIvy"
ref = "http://blog.cylance.com/a-study-in-bots-blackshades-net"
family = "blackshades"
strings:
$string1 = "bss_server"
$string2 = "txtChat"
$string3 = "UDPFlood"
condition:
all of them
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment