Commit 59a245a7 by Bondey

emotet Packer update

parent b94708a5
...@@ -20,10 +20,11 @@ rule emotet_packer { ...@@ -20,10 +20,11 @@ rule emotet_packer {
reference = "e31028282c38cb13dd4ede7e9c8aa62d45ddae5ebaa0fe3afb3256601dbf5de7" reference = "e31028282c38cb13dd4ede7e9c8aa62d45ddae5ebaa0fe3afb3256601dbf5de7"
date = "2017-12-12" date = "2017-12-12"
strings: strings:
$pdb = "123EErrrtools.pdb" $pdb1 = "123EErrrtools.pdb"
$pdb2= "gGEW\\F???/.pdb"
condition: condition:
$pdb $pdb1 or $pdb2
} }
rule silent_banker : banker rule silent_banker : banker
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment