Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule susp_Excel_Macrosheets_Bulk {
- meta:
- desc = "Detects suspicious excel macrosheets artifacts"
- author = "James Quinn"
- strings:
- $artifact1 = {43 00 3A 00 5C 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 00 00}
- $artifact2 = {5C 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 2E 00 65 00 78 00 65}
- $artifact6 = {43 00 3A 00 5C 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 00 00}
- $artifact3 = {5c 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 2e 00 ?? 00 ?? 00}
- $artifact4 = {5c 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 2e 00 64 00 6c 00 6c 00 00}
- $artifact5 = {43 00 3A 00 5C 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 00 00}
- $artifact7 = {43 3a 5c ?? ?? ?? ?? ??}
- $import1 = "load" wide nocase
- $import2 = "load" nocase
- $openStr = "Docusign" nocase
- $proto = "http"
- condition:
- (uint16(0) == 0x4b50 or uint32be(0) == 0x81010093 or uint32be(0) == 0xD0CF11E0) and
- filesize < 1000KB and
- 1 of ($artifact*) and $openStr and 1 of ($import*) and $proto
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement