Commit c411c30e by mmorenog

Update RomeoAlfa.yara

parent 721ad18a
...@@ -18,15 +18,7 @@ rule RomeoAlfa ...@@ -18,15 +18,7 @@ rule RomeoAlfa
7C E7 jl short loc_4039DA 7C E7 jl short loc_4039DA
*/ */
$zeroIPLoader = { $zeroIPLoader = {68 [4] 56 E8 [4] 83 C6 28 83 C4 08 81 FE [4] 7C E?}
68 [4]
56
E8 [4]
83 C6 28
83 C4 08
81 FE [4]
7C E?
}
...@@ -43,21 +35,7 @@ rule RomeoAlfa ...@@ -43,21 +35,7 @@ rule RomeoAlfa
// pop edi // pop edi
// pop esi // pop esi
// retn // retn
$sleeper = { $sleeper = {5? 8B [3] 85 ?? 7E ?? 5? 8B 3D [4] 68 [4] FF ?? 4? 75 ?? 5? 5? C3 }
5?
8B [3]
85 ??
7E ??
5?
8B 3D [4]
68 [4]
FF ??
4?
75 ??
5?
5?
C3
}
$xercesc = "xercesc" $xercesc = "xercesc"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment