Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule encrypted_zip_emotet
- {
- strings:
- $re1 = /Mot de passe: [0-9a-zA-Z]{5,7}/
- $re2 = /Password - [0-9a-zA-Z]{5,7}/
- $re3 = /Password: [0-9a-zA-Z]{5,7}/
- $re4 = /The password for the document is/
- $attachment = ".zip" nocase
- condition:
- ($re1 or $re2 or $re3 or $re4) and $attachment
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement