Commit fd56b86b by mmorenog

Update RomeoHotel.yara

parent 39f96de1
......@@ -25,19 +25,7 @@ rule RomeoHotel
41 83 C4 3C add r12d, 3Ch
*/
$randBuff64 = { E8 [4]
44 [2]
44 [2]
B? 1F 85 EB 51
48 [2]
41 [2]
C1 ?? 05
8B ??
C1 ?? 1F
03 ??
6B ?? 64
44 [2]
41 [2] 3C}
$randBuff64 = {E8 [4] 44 [2] 44 [2] B? 1F 85 EB 51 48 [2] 41 [2] C1 ?? 05 8B ?? C1 ?? 1F 03 ?? 6B ?? 64 44 [2] 41 [2] 3C}
/*
FF 15 40 70 01 10 call ds:GetDiskFreeSpaceExA
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment