Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- private rule Macho
- {
- meta:
- description = "private rule to match Mach-O binaries (copied from Apple's XProtect)"
- condition:
- uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca
- }
- rule ZoomDaemon
- {
- meta:
- description = "ZoomDaemon and its whitelabels"
- strings:
- $ = "zLocalHostWrapper"
- $ = "ZMClientHelper"
- $ = "ZMLocalHostMgr"
- condition:
- Macho and all of them
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement