Unverified Commit 9e613bc0 by jovimon Committed by GitHub

Move is__elf to MISC_Utils.yar

parent 975d251f
......@@ -59,15 +59,6 @@ private rule is__bot_Rebirth_gen3 {
6 of them
}
private rule is__elf {
meta:
author = "@mmorenog,@yararules"
strings:
$header = { 7F 45 4C 46 }
condition:
$header at 0
}
rule MALW_Rebirth_Vulcan_ELF {
meta:
description = "Detects Rebirth Vulcan variant a torlus NextGen MALW"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment