Commit 59a245a7 by Bondey

emotet Packer update

parent b94708a5
......@@ -20,10 +20,11 @@ rule emotet_packer {
reference = "e31028282c38cb13dd4ede7e9c8aa62d45ddae5ebaa0fe3afb3256601dbf5de7"
date = "2017-12-12"
strings:
$pdb = "123EErrrtools.pdb"
$pdb1 = "123EErrrtools.pdb"
$pdb2= "gGEW\\F???/.pdb"
condition:
$pdb
$pdb1 or $pdb2
}
rule silent_banker : banker
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment