Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule biff5
- {
- meta:
- author = "DissectMalware"
- strings:
- $biff5 = { 42 00 6F 00 6F 00 6B 00 00 00 [54] 0A }
- $ole_marker = { D0 CF 11 E0 A1 B1 1A E1 }
- condition:
- $ole_marker at 0 and $biff5
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement