Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule MSEXCELOB_KINDALOOSE {
- meta:
- version=".2"
- filetype="csv'ish"
- author="Ian.Ahl@TekDefense.com @TekDefense"
- date="2017-03-22"
- hashes="996f296283c594f233cdc6ad208b273d"
- strings:
- // command
- $com1 = "=MSEXCEL|'\\.." ascii wide
- $com2 = "\"ms at fo\"" ascii wide
- $com3 = "do call %ihta" ascii wide
- $com4 = "http" ascii wide
- condition:
- ( uint16(0) != 0x5a4d)
- and
- (2 of them)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement