Commit 5724d582 by mmorenog

Update WhiskeyDelta.yara

parent b8ad7692
......@@ -32,29 +32,7 @@ rule WhiskeyDelta
42 inc edx
*/
$decryption = {
F3 A5
8B 7C 24 30
85 FF
7E ??
8B 74 24 2C
8A 44 24 08
53
8A 4C 24 21
8A 5C 24 2B
32 C1
8A 0C 32
32 C3
32 C8
88 0C 32
B9 1E 00 00 00
8A 5C 0C 0C
88 5C 0C 0D
49
83 F9 FF
7F ??
42
}
$decryption = {F3 A5 8B 7C 24 30 85 FF 7E ?? 8B 74 24 2C 8A 44 24 08 53 8A 4C 24 21 8A 5C 24 2B 32 C1 8A 0C 32 32 C3 32 C8 88 0C 32 B9 1E 00 00 00 8A 5C 0C 0C 88 5C 0C 0D 49 83 F9 FF 7F ?? 42 }
$s1 = "=====IsFile=====" wide
$s2 = "=====4M=====" wide
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment