Unverified Commit 76d87e8f by j0sm1 Committed by GitHub

Updated and renamed name file APT_FIN7

parent 18095a6f
...@@ -2,14 +2,14 @@ ...@@ -2,14 +2,14 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule fin7_functions rule Cobalt_functions
{ {
meta: meta:
author="@j0sm1" author="@j0sm1"
url="https://www.securityartwork.es/2017/06/16/analisis-del-powershell-usado-fin7/" url="https://www.securityartwork.es/2017/06/16/analisis-del-powershell-usado-fin7/"
description="Detect functions coded with ROR edi,D" description="Detect functions coded with ROR edi,D; Detect CobaltStrike used by differents groups APT"
strings: strings:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment