diff --git a/malware/Operation_Blockbuster/IndiaHotel.yara b/malware/Operation_Blockbuster/IndiaHotel.yara index e76ec37..414c47b 100644 --- a/malware/Operation_Blockbuster/IndiaHotel.yara +++ b/malware/Operation_Blockbuster/IndiaHotel.yara @@ -16,13 +16,7 @@ rule IndiaHotel E8 FA 60 00 00 call ??_L@YGXPAXIHP6EX0@Z1@Z; `eh vector constructor iterator'(void *,uint,int,void (*)(void *),void (*)(void *)) */ - $fileExtractorArraySetup = { - 6A 0A - 8D [5-6] - 68 10 02 00 00 - 50 - E8 - } + $fileExtractorArraySetup = {6A 0A 8D [5-6] 68 10 02 00 00 50 E8} condition: $fileExtractorArraySetup in ((pe.sections[pe.section_index(".text")].raw_data_offset)..(pe.sections[pe.section_index(".text")].raw_data_offset + pe.sections[pe.section_index(".text")].raw_data_size))