Commit cce235cc by Marc Rivero López Committed by GitHub

Update APT_DeputyDog.yar

Fixed style rule
parent 093d7832
...@@ -4,22 +4,26 @@ ...@@ -4,22 +4,26 @@
import "pe" import "pe"
rule APT_DeputyDog_Fexel : APT DeputyDog rule APT_DeputyDog_Fexel
{ {
meta: meta:
author = "ThreatConnect Intelligence Research Team" author = "ThreatConnect Intelligence Research Team"
strings: strings:
$180 = "180.150.228.102" wide ascii $180 = "180.150.228.102" wide ascii
$0808cmd = {25 30 38 78 30 38 78 00 5C 00 63 00 6D 00 64 00 2E 00 65 00 78 00 65 [2-6] 43 00 61 00 6E 00 27 00 74 00 20 00 6F 00 70 00 65 00 6E 00 20 00 73 00 68 00 65 00 6C 00 6C 00 21} $0808cmd = {25 30 38 78 30 38 78 00 5C 00 63 00 6D 00 64 00 2E 00 65 00 78 00 65 [2-6] 43 00 61 00 6E 00 27 00 74 00 20 00 6F 00 70 00 65 00 6E 00 20 00 73 00 68 00 65 00 6C 00 6C 00 21}
$cUp = "Upload failed! [Remote error code:" nocase wide ascii $cUp = "Upload failed! [Remote error code:" nocase wide ascii
$DGGYDSYRL = {00 44 47 47 59 44 53 59 52 4C 00} $DGGYDSYRL = {00 44 47 47 59 44 53 59 52 4C 00}
$GDGSYDLYR = "GDGSYDLYR_%" wide ascii $GDGSYDLYR = "GDGSYDLYR_%" wide ascii
condition: condition:
any of them any of them
} }
rule APT_DeputyDog : APT DeputyDog rule APT_DeputyDog
{ {
meta: meta:
Author = "FireEye Labs" Author = "FireEye Labs"
Date = "2013/09/21" Date = "2013/09/21"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment