Commit f154601c by mmorenog

Update Miscelanea.yar

parent b0ade30d
...@@ -1229,4 +1229,25 @@ rule CVE_2015_1674_CNGSYS { ...@@ -1229,4 +1229,25 @@ rule CVE_2015_1674_CNGSYS {
$s5 = "ntdll.dll" fullword ascii $s5 = "ntdll.dll" fullword ascii
condition: condition:
uint16(0) == 0x5a4d and filesize < 60KB and all of them uint16(0) == 0x5a4d and filesize < 60KB and all of them
} }
\ No newline at end of file rule Ap0calypse
{
meta:
author = " Kevin Breen <kevin@techanarchy.net>"
date = "2014/04"
ref = "http://malwareconfig.com/stats/Ap0calypse"
maltype = "Remote Access Trojan"
filetype = "exe"
strings:
$a = "Ap0calypse"
$b = "Sifre"
$c = "MsgGoster"
$d = "Baslik"
$e = "Dosyalars"
$f = "Injecsiyon"
condition:
all of them
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment