Commit cdea5767 by mmorenog Committed by GitHub

Update APT_UP007_SLServer.yar

parent 91b56f91
...@@ -30,7 +30,7 @@ rule dubseven_file_set ...@@ -30,7 +30,7 @@ rule dubseven_file_set
3 of ($file*) 3 of ($file*)
} }
rule dubseven_dropper_registry_checks rule dubseven_dropper_registry_checks : Dropper
{ {
meta: meta:
author = "Matt Brooks, @cmatthewbrooks" author = "Matt Brooks, @cmatthewbrooks"
...@@ -55,7 +55,7 @@ rule dubseven_dropper_registry_checks ...@@ -55,7 +55,7 @@ rule dubseven_dropper_registry_checks
all of ($reg*) all of ($reg*)
} }
rule dubseven_dropper_dialog_remains rule dubseven_dropper_dialog_remains : Dropper
{ {
meta: meta:
author = "Matt Brooks, @cmatthewbrooks" author = "Matt Brooks, @cmatthewbrooks"
...@@ -76,7 +76,7 @@ rule dubseven_dropper_dialog_remains ...@@ -76,7 +76,7 @@ rule dubseven_dropper_dialog_remains
} }
rule maindll_mutex rule maindll_mutex : Mutex
{ {
meta: meta:
author = "Matt Brooks, @cmatthewbrooks" author = "Matt Brooks, @cmatthewbrooks"
...@@ -117,7 +117,7 @@ rule SLServer_dialog_remains ...@@ -117,7 +117,7 @@ rule SLServer_dialog_remains
$slserver $slserver
} }
rule SLServer_mutex rule SLServer_mutex : Mutex
{ {
meta: meta:
author = "Matt Brooks, @cmatthewbrooks" author = "Matt Brooks, @cmatthewbrooks"
...@@ -137,7 +137,7 @@ rule SLServer_mutex ...@@ -137,7 +137,7 @@ rule SLServer_mutex
$mutex $mutex
} }
rule SLServer_command_and_control rule SLServer_command_and_control : C2
{ {
meta: meta:
author = "Matt Brooks, @cmatthewbrooks" author = "Matt Brooks, @cmatthewbrooks"
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment