Commit 7f4fc3cd by Marc Rivero López Committed by GitHub

Update APT_Backspace.yar

Fixed rule style
parent 29d900f4
...@@ -2,16 +2,20 @@ ...@@ -2,16 +2,20 @@
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/ */
rule apt_backspace{ rule apt_backspace
meta: {
description = "Detects APT backspace"
author = "Bit Byte Bitten" meta:
date = "2015-05-14" description = "Detects APT backspace"
hash = "6cbfeb7526de65eb2e3c848acac05da1e885636d17c1c45c62ad37e44cd84f99" author = "Bit Byte Bitten"
strings: date = "2015-05-14"
$s1 = "!! Use Splice Socket !!" hash = "6cbfeb7526de65eb2e3c848acac05da1e885636d17c1c45c62ad37e44cd84f99"
$s2 = "User-Agent: SJZJ (compatible; MSIE 6.0; Win32)"
$s3 = "g_nAV=%d,hWnd:0x%X,className:%s,Title:%s,(%d,%d,%d,%d),BOOL=%d" strings:
condition: $s1 = "!! Use Splice Socket !!"
uint16(0) == 0x5a4d and all of them $s2 = "User-Agent: SJZJ (compatible; MSIE 6.0; Win32)"
$s3 = "g_nAV=%d,hWnd:0x%X,className:%s,Title:%s,(%d,%d,%d,%d),BOOL=%d"
condition:
uint16(0) == 0x5a4d and all of them
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment