Commit 55c09c7d by mmorenog

Update RomeoHotel.yara

parent f14a60f2
...@@ -40,16 +40,7 @@ rule RomeoHotel ...@@ -40,16 +40,7 @@ rule RomeoHotel
E8 4C 7C 00 00 call __allmul E8 4C 7C 00 00 call __allmul
*/ */
$diskSpace = {FF 15 [4] $diskSpace = {FF 15 [4] 85 C0 74 ?? 8B [6] 6A 00 99 68 00 00 10 00 5? 5? E8}
85 C0
74 ??
8B [6]
6A 00
99
68 00 00 10 00
5?
5?
E8}
$winst = "winsta0\\default" wide // this limits the overlap with RomeoGolf $winst = "winsta0\\default" wide // this limits the overlap with RomeoGolf
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment