Advertisement
James_inthe_box

Signed azo yara

Jan 28th, 2019
430
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.65 KB | None | 0 0
  1. rule Sign_azo
  2. {
  3. meta:
  4. description = "Signed azorult"
  5. author = "James_inthe_box"
  6. reference = "796e6d59f5cbc3eba40c08c9a4c1002677bbf2be75a7dc3fd779a7f133a49e83"
  7. date = "2019/01"
  8. maltype = "Infotealer"
  9.  
  10. strings:
  11. $mz = { 4d 5a }
  12. $string1 = "GoogleUpdate.exe" wide
  13. $string2 = "Google Inc." wide
  14. $string3 = "1.3.29.1" wide
  15. $string4 = "041904e3" wide
  16. $string5 = "info@singh-content.co.uk"
  17. $string6 = "London1806"
  18. $string7 = "Singh Agile Content Design Limited"
  19.  
  20. condition:
  21. ($mz at 0) and (all of ($string*)) and filesize < 1400KB
  22. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement