Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule zeus
- {
- meta:
- author = " James_inthe_box"
- date = "2018/10"
- maltype = "Zeus"
- strings:
- //$c1 = "%BOTID%"
- //$c2 = "%BOTNET%"
- $s1 = "http://www.google.com/webhp"
- $s2 = "Global\\%08X%08X%08X" wide
- $s3 = "RFB 003.003"
- $s4 = "%s%08x.%s" wide
- condition:
- 3 of ($s*)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement