Commit 6db38592 by mmorenog Committed by GitHub

Update and rename APT_putterpanda.yar to APT_PutterPanda.yar

parent 7364f1fa
...@@ -125,7 +125,7 @@ rule APT_Malware_PutterPanda_Gen1 { ...@@ -125,7 +125,7 @@ rule APT_Malware_PutterPanda_Gen1 {
uint16(0) == 0x5a4d and filesize < 1000KB and 5 of them uint16(0) == 0x5a4d and filesize < 1000KB and 5 of them
} }
rule Malware_MsUpdater_String_in_EXE { rule Malware_MsUpdater_String_in_EXE : PutterPanda {
meta: meta:
description = "MSUpdater String in Executable" description = "MSUpdater String in Executable"
author = "Florian Roth" author = "Florian Roth"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment