Commit a7f62a23 by mmorenog Committed by GitHub

Update APT_Passcv.yar

parent 8bbfa9f7
......@@ -159,3 +159,4 @@ rule PassCV_Sabre_Malware_5 {
$s5 = "SHARECONTROL" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 4000KB and 1 of ($x*) or all of ($s*) )
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment