Commit 791706f1 by Your Mom

new rule for hancitor botnet malware

parent af2f40f6
rule hancitor {
description = "Memory string yara for Hancitor"
author = "J from THL <>"
reference1 = ""
reference2 = ""
reference3 = ""
date = "2018-09-18"
maltype1 = "Botnet"
filetype = "memory"
$a = "GUID=" ascii
$b = "&BUILD=" ascii
$c = "&INFO=" ascii
$d = "&IP=" ascii
$e = "&TYPE=" ascii
$f = "php|http" ascii
$g = "GUID=%I64u&BUILD=%s&INFO=%s&IP=%s&TYPE=1&WIN=%d.%d" ascii fullword
5 of ($a,$b,$c,$d,$e,$f) or $g
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment