Commit b577e473 by mmorenog

Update LimaBravo.yara

parent 19fc17cc
......@@ -20,16 +20,7 @@ rule LimaBravo
E8 97 01 00 00 call ManualImageLoad
*/
$a = {
83 ?? 34
83 ?? 0A
[0-2]
7E ??
5?
C6 ?? 4D
C6 [2] 5A
E8
}
$a = {83 ?? 34 83 ?? 0A [0-2] 7E ?? 5? C6 ?? 4D C6 [2] 5A E8}
condition:
$a in ((pe.sections[pe.section_index(".text")].raw_data_offset)..(pe.sections[pe.section_index(".text")].raw_data_offset + pe.sections[pe.section_index(".text")].raw_data_size))
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment