Commit c456c0aa by mmorenog Committed by GitHub

Update and rename DarkComet.yar to RAT_DarkComet.yar

parent f56f1137
...@@ -5,7 +5,7 @@ ...@@ -5,7 +5,7 @@
import "pe" import "pe"
rule DarkComet_1 rule DarkComet_1 : RAT
{ {
meta: meta:
description = "DarkComet RAT" description = "DarkComet RAT"
...@@ -57,7 +57,7 @@ rule DarkComet_2 : rat ...@@ -57,7 +57,7 @@ rule DarkComet_2 : rat
condition: condition:
any of them any of them
} }
rule DarkComet_3 rule DarkComet_3 : RAT
{ {
meta: meta:
author = " Kevin Breen <kevin@techanarchy.net>" author = " Kevin Breen <kevin@techanarchy.net>"
...@@ -82,7 +82,7 @@ rule DarkComet_3 ...@@ -82,7 +82,7 @@ rule DarkComet_3
all of ($a*) or all of ($b*) all of ($a*) or all of ($b*)
} }
rule DarkComet_Keylogger_File rule DarkComet_Keylogger_File : RAT
{ {
meta: meta:
author = "Florian Roth" author = "Florian Roth"
...@@ -97,7 +97,7 @@ rule DarkComet_Keylogger_File ...@@ -97,7 +97,7 @@ rule DarkComet_Keylogger_File
condition: condition:
($magic at 0) and #entry > 10 and #timestamp > 10 ($magic at 0) and #entry > 10 and #timestamp > 10
} }
rule DarkComet_4 rule DarkComet_4 : RAT
{ meta: { meta:
reference = "https://github.com/bwall/bamfdetect/blob/master/BAMF_Detect/modules/yara/darkcomet.yara" reference = "https://github.com/bwall/bamfdetect/blob/master/BAMF_Detect/modules/yara/darkcomet.yara"
strings: strings:
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment