Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- artifiacts
- hyuder.exe
- C:\barebareseh\spainkl\60-Restaurant\Restaurant Master.vbp
- C:\barebareseh\spainkl\56 - cdexplore\prjcdhtmlexp.vbp
- C:\comyeapna\chukahai\new project - 27\Project1.vbp
- b15159115e17a28c1e1bda2151fddb8b0289ed12078309be982cf885f03ec126
- 7a95219d97fb2ea650886fb84dfda9aa874123b7cef5b387de5aebcec3b82097
- 54a9855383674e1b5bb22d719846cfc76758bca65804b0fd217bc2efa28250de
- yara sig
- rule Kutaki_bin
- {
- meta:
- description = "Kutaki"
- author = " James_inthe_box"
- reference = "54a9855383674e1b5bb22d719846cfc76758bca65804b0fd217bc2efa28250de"
- date = "2019/01"
- maltype = "Bot"
- strings:
- $mz = { 4d 5a }
- $string1 = "S u r e" wide
- $string2 = "saverbro" wide
- $string3 = "Want To Clear Log" wide
- $string4 = "achibat" wide
- $string5 = "LoginSucceeded"
- condition:
- ($mz at 0) and (all of ($string*))
- }
- rule Kutaki_mem
- {
- meta:
- description = "Kutaki"
- author = " James_inthe_box"
- reference = "54a9855383674e1b5bb22d719846cfc76758bca65804b0fd217bc2efa28250de"
- date = "2019/01"
- maltype = "Bot"
- strings:
- $string1 = "S u r e" wide
- $string2 = "saverbro" wide
- $string3 = "Want To Clear Log" wide
- $string4 = "achibat" wide
- $string5 = "LoginSucceeded"
- condition:
- all of ($string*)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement