Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule netwire_modded_04_2019 {
- strings:
- $s1="ping 192.0.2.2 -n 1 -w %d >nul 2>&1"
- $s2="@echo off"
- $s3="DEL /s \"%s\" >nul 2>&1"
- $s4="call :deleteSelf&exit /b"
- $s5=":deleteSelf"
- $s6="start /b \"\" cmd /c del \"%%~f0\"&"
- $s7="[Log Started] - [%.2d/%.2d/%d %.2d:%.2d:%.2d]"
- $s8="[%s] - [%.2d/%.2d/%d %.2d:%.2d:%.2d]"
- $s9="%s%.2d-%.2d-%.4d"
- $s10="Settings.ini"
- $s11="GET %s HTTP/1.1"
- $s12="%s\\%s.bat"
- $s13="This is element 0: %s"
- $s14="%.2d/%.2d/%d %.2d:%.2d:%.2d"
- $s15="%c%.8x%s\\%s"
- $s16="%c%.8x%s%s"
- $s17="%c%.8x%s"
- $s18="%s\\%s"
- $s19="%d:%I64u:%s%s;"
- $s20="Host: %s"
- $strings_dec={C6 44 24 ?? ?? C7 44 24 ?? ?? ?? ?? ?? 8B 44 24 ?? 89 44 24 ?? C7 44 24 ?? ?? ?? ?? ?? C7 44 24 ?? 04 01 00 00 C7 04 24 ?? ?? ?? ?? E8 ?? ?? ?? ?? C7 44 24 ?? 00 00 00 00 EB}
- condition:
- ((17 of ($s*)) or $strings_dec)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement