Commit 971454af by jovimon Committed by GitHub

Merge pull request #171 from Antelox/patch-5

Fixed syntax error in petya rules
parents 5374c0b0 8579a7ee
...@@ -31,15 +31,15 @@ rule Petya_Ransomware { ...@@ -31,15 +31,15 @@ rule Petya_Ransomware {
uint16(0) == 0x5a4d and filesize < 500KB and $a1 and 3 of ($s*) uint16(0) == 0x5a4d and filesize < 500KB and $a1 and 3 of ($s*)
} }
rule Ransom.Petya { rule Ransom_Petya {
meta: meta:
description = "Regla para detectar Ransom.Petya con md5 AF2379CC4D607A45AC44D62135FB7015" description = "Regla para detectar Ransom.Petya con md5 AF2379CC4D607A45AC44D62135FB7015"
author = "CCN-CERT”" author = "CCN-CERT"
version = "1.0" version = "1.0"
strings: strings:
$ = { C1 C8 14 2B F0 03 F0 2B F0 03 F0 C1 C0 14 03 C2 } $a1 = { C1 C8 14 2B F0 03 F0 2B F0 03 F0 C1 C0 14 03 C2 }
$ = { 46 F7 D8 81 EA 5A 93 F0 12 F7 DF C1 CB 10 81 F6 } $a2 = { 46 F7 D8 81 EA 5A 93 F0 12 F7 DF C1 CB 10 81 F6 }
$ = { 0C 88 B9 07 87 C6 C1 C3 01 03 C5 48 81 C3 A3 01 00 00 } $a3 = { 0C 88 B9 07 87 C6 C1 C3 01 03 C5 48 81 C3 A3 01 00 00 }
condition: condition:
all of them all of them
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment