Commit 7747d094 by mmorenog

Update IndiaJuliett.yara

parent b7682be4
...@@ -48,21 +48,7 @@ rule IndiaJuliett ...@@ -48,21 +48,7 @@ rule IndiaJuliett
81 C6 00 28 00 00 add esi, 2800h 81 C6 00 28 00 00 add esi, 2800h
*/ */
$writeFile = { $writeFile = {68 00 28 00 00 5? E8 [4-7] 8D [3] 6A 00 5? 68 00 28 00 00 5? 5? FF 15 [4] 81 ?? 00 28 00 00 81 ?? 00 28 00 00 81 ?? 00 28 00 00}
68 00 28 00 00
5?
E8 [4-7]
8D [3]
6A 00
5?
68 00 28 00 00
5?
5?
FF 15 [4]
81 ?? 00 28 00 00
81 ?? 00 28 00 00
81 ?? 00 28 00 00
}
condition: condition:
($configFilename in ((pe.sections[pe.section_index(".data")].raw_data_offset)..(pe.sections[pe.section_index(".data")].raw_data_offset + pe.sections[pe.section_index(".data")].raw_data_size)) or ($configFilename in ((pe.sections[pe.section_index(".data")].raw_data_offset)..(pe.sections[pe.section_index(".data")].raw_data_offset + pe.sections[pe.section_index(".data")].raw_data_size)) or
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment