Commit 6bbcdd24 by Marc Rivero López Committed by GitHub

Update APT_NGO.yar

parent e55e40ee
...@@ -7,8 +7,10 @@ import "pe" ...@@ -7,8 +7,10 @@ import "pe"
rule APT_NGO_wuaclt rule APT_NGO_wuaclt
{ {
meta: meta:
author = "AlienVault Labs" author = "AlienVault Labs"
strings: strings:
$a = "%%APPDATA%%\\Microsoft\\wuauclt\\wuauclt.dat" $a = "%%APPDATA%%\\Microsoft\\wuauclt\\wuauclt.dat"
$b = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)" $b = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment