Unverified Commit 5d158252 by unixfreaxjp Committed by GitHub

Update MALW_IcedID.yar

parent d151b532
...@@ -26,7 +26,7 @@ rule IceID_bank_trojan { ...@@ -26,7 +26,7 @@ rule IceID_bank_trojan {
$st08 = "AVCUserException@@" fullword nocase wide ascii $st08 = "AVCUserException@@" fullword nocase wide ascii
condition: condition:
header at 0 and all of ($magic*) and 6 of ($st0*) $header at 0 and all of ($magic*) and 6 of ($st0*)
and pe.sections[0].name contains ".text" and pe.sections[0].name contains ".text"
and pe.sections[1].name contains ".rdata" and pe.sections[1].name contains ".rdata"
and pe.sections[2].name contains ".data" and pe.sections[2].name contains ".data"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment