Update win_apt_chafer_mar18.yml

This commit is contained in:
Jonhnathan 2020-10-15 20:30:52 -03:00 committed by GitHub
parent 1fac65dad0
commit 37ee747dfe
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -74,7 +74,7 @@ detection:
CommandLine|startswith:
- 'C:\wsc.exe'
selection_process2:
Image|startswith: '\Windows\Temp\DB\\*.exe'
Image|endswith: '\Windows\Temp\DB\\*.exe'
selection_process3:
CommandLine|contains: '\nslookup.exe -q=TXT'
ParentImage|contains: '\Autoit'