MalwareQuinn

DoejoCrypt.yar

Mar 12th, 2021 (edited)
11,949
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.38 KB | None | 0 0
  1. rule DoejoCrypt {
  2. meta:
  3. description = "DoejoCrypt Detection"
  4. author = "James Quinn"
  5. date = "March 12 2021"
  6. tlp = "White"
  7. strings:
  8. $s1 = {C7 ?? 01 23 45 67 C7 ?? ?? 89 AB CD EF C7 ?? ?? FE DC BA 98 C7 ?? ?? 76 54 32 10}
  9. $s2 = {7C ?? 3C 5A 7E ?? 3C 63 0F ?? ?? ?? ?? ?? 3C 7A}
  10. $s3 = {2B C7 03 C2 3D 14 05 00 00}
  11. condition:
  12. all of them
  13. }
  14.  
Add Comment
Please, Sign In to add comment