Commit ae3a1f9f by mmorenog

Update SierraBravo.yara

parent 52d63110
......@@ -33,18 +33,7 @@ rule SierraBravo_Two
.text:10003721 mov word ptr [ebx+29h], 4104h
.text:10003727 mov word ptr [ebx+2Bh], 32h
*/
$smbComNegotiationPacketGen = { 66 C7 ?? 0E 07 C8
[0-32]
C7 ?? 39 D4 00 00 80
[0-32]
66 C7 ?? 25 FF 00
[0-32]
66 C7 ?? 27 A4 00
[0-32]
66 C7 ?? 29 04 41
[0-32]
66 C7 ?? 2B 32 00
}
$smbComNegotiationPacketGen = { 66 C7 ?? 0E 07 C8 [0-32] C7 ?? 39 D4 00 00 80 [0-32] 66 C7 ?? 25 FF 00 [0-32] 66 C7 ?? 27 A4 00 [0-32] 66 C7 ?? 29 04 41 [0-32] 66 C7 ?? 2B 32 00}
$lib = "!emCFgv7Xc8ItaVGN0bMf"
$api1 = "!ctRHFEX5m9JnZdDfpK"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment