This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
*/
rule Windows_Malware_Azorult : Azorult_V2
import "cuckoo"
rule Windows_Malware : Azorult_V2
{
{
meta:
meta:
author = "Xylitol xylitol@temari.fr"
author = "Xylitol xylitol@temari.fr"
date = "2017-09-30"
date = "2017-09-30"
description = "Match first two bytes, strings, and parts of routines present in Azorult"
description = "Match first two bytes, strings, and parts of routines present in Azorult"