diff --git a/Malicious_Documents/Maldoc_Suspicious_OLE_target.yar b/Malicious_Documents/Maldoc_Suspicious_OLE_target.yar index deb9c3e..886465e 100644 --- a/Malicious_Documents/Maldoc_Suspicious_OLE_target.yar +++ b/Malicious_Documents/Maldoc_Suspicious_OLE_target.yar @@ -3,6 +3,7 @@ rule Maldoc_Suspicious_OLE_target { description = "Detects maldoc With Tartgeting Suspicuios OLE" author = "Donguk Seo" reference = "https://blog.malwarebytes.com/threat-analysis/2017/10/decoy-microsoft-word-document-delivers-malware-through-rat/" + filetype = "Office documents" date = "2018-06-13" strings: $env1 = /oleObject".*Target=.*.http.*.doc"/