Commit b310ec8f by mmorenog

Update Ramsonware.yar

Add rule to detects a tiny SVG file that loads an URL (as seen in CryptoWall malware infections)
parent fc0544da
...@@ -63,3 +63,22 @@ condition: ...@@ -63,3 +63,22 @@ condition:
8 of ($string*) 8 of ($string*)
} }
rule SVG_LoadURL {
meta:
description = "Detects a tiny SVG file that loads an URL (as seen in CryptoWall malware infections)"
author = "Florian Roth"
reference = "http://goo.gl/psjCCc"
date = "2015-05-24"
hash1 = "ac8ef9df208f624be9c7e7804de55318"
hash2 = "3b9e67a38569ebe8202ac90ad60c52e0"
hash3 = "7e2be5cc785ef7711282cea8980b9fee"
hash4 = "4e2c6f6b3907ec882596024e55c2b58b"
score = 50
strings:
$s1 = "</svg>" nocase
$s2 = "<script>" nocase
$s3 = "location.href='http" nocase
condition:
all of ($s*) and filesize < 600
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment