Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule Netwire_mod_bin
- {
- meta:
- description = "Modded netwire"
- author = "James_inthe_box"
- reference = ""
- date = "2019/01"
- maltype = "RAT"
- strings:
- $mz = { 4d 5a }
- $string1 = "Unknown"
- $string2 = "call :deleteSelf&exit /b"
- $string3 = "__WSAFDIsSet"
- $string4 = "DEL /s \"%s\" >nul 2>&1"
- $string5 = "[%s] - [%.2d/%.2d/%d %.2d:%.2d:%.2d]"
- $string6 = "localhost"
- $string7 = "Host.exe"
- $string8 = "This is element 0: %s"
- $string9 = "[D00Wg us]"
- $string10 = "[Log Started]"
- $string11 = "Mozilla Thunderbird"
- $string12 = "ping 192.0.2.2 -n 1 -w %d >nul 2>&1"
- condition:
- $mz at 0 and (all of ($string*)) and filesize < 800KB
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement