Commit 94c77f0d by pekeinfo

New rule Cerber5

parent 42ce5248
......@@ -41,3 +41,15 @@ strings:
condition:
1 of them
}
rule cerber5b{
meta:
author = "pekeinfo"
date = "2016-12-20"
description = "Cerber5b"
strings:
$a={8B ?? ?8 ?? 4? 00 83 E? 02 89 ?? ?8 ?? 4? 00 68 ?C ?9 4? 00 [0-6] ?? ?? ?? ?? ?? ?8 ?? 4? 00 5? FF 15 ?? ?9 4? 00 89 45 ?4 83 7D ?4 00 75 02 EB 12 8B ?? ?0 83 C? 06 89 ?? ?0 B? DD 03 00 00 85}
condition:
$a
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment