Commit 6a77cc41 by mmorenog

Update Equation.yar

parent 0b718b79
......@@ -5,9 +5,6 @@
import "pe"
/* Equation APT ------------------------------------------------------------ */
rule apt_equation_exploitlib_mutexes {
......@@ -571,3 +568,26 @@ rule EquationDrug_FileSystem_Filter {
condition:
all of them
}
rule apt_equation_keyword {
meta:
description = "Rule to detect Equation group's keyword in executable file"
last_modified = "2015-09-26"
reference = "http://securelist.com/blog/research/68750/equation-the-death-star-of-malware-galaxy/"
strings:
$a1 = "Backsnarf_AB25" wide
$a2 = "Backsnarf_AB25" ascii
condition:
uint16(0) == 0x5a4d and 1 of ($a*)
}
rule apt_equation_keyword {
meta:
description = "Rule to detect Equation group's keyword in executable file"
last_modified = "2015-09-26"
reference = "http://securelist.com/blog/research/68750/equation-the-death-star-of-malware-galaxy/"
strings:
$a1 = "Backsnarf_AB25" wide
$a2 = "Backsnarf_AB25" ascii
condition:
uint16(0) == 0x5a4d and 1 of ($a*)
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment