From 679aabd7d1267b419bd7af4e863caa5f96150e61 Mon Sep 17 00:00:00 2001 From: mmorenog <mmorenog@users.noreply.github.com> Date: Wed, 20 Jul 2016 11:12:48 +0200 Subject: [PATCH] Update APT_Irontiger_Trendmicro.yar --- malware/APT_Irontiger_Trendmicro.yar | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/malware/APT_Irontiger_Trendmicro.yar b/malware/APT_Irontiger_Trendmicro.yar index 770f922..1fd7886 100644 --- a/malware/APT_Irontiger_Trendmicro.yar +++ b/malware/APT_Irontiger_Trendmicro.yar @@ -159,7 +159,7 @@ rule IronTiger_GTalk_Trojan uint16(0) == 0x5a4d and (2 of ($str*)) } -rule IronTiger_HTTPBrowser_Dropper +rule IronTiger_HTTPBrowser_Dropper : Dropper { meta: author = "Cyber Safety Solutions, Trend Micro" @@ -189,7 +189,7 @@ rule IronTiger_HTTP_SOCKS_Proxy_soexe uint16(0) == 0x5a4d and (3 of ($str*)) } -rule IronTiger_NBDDos_Gh0stvariant_dropper +rule IronTiger_NBDDos_Gh0stvariant_dropper : Dropper { meta: author = "Cyber Safety Solutions, Trend Micro" -- libgit2 0.26.0