mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_apt_chafer_mar18.yml
This commit is contained in:
parent
1fac65dad0
commit
37ee747dfe
@ -74,7 +74,7 @@ detection:
|
||||
CommandLine|startswith:
|
||||
- 'C:\wsc.exe'
|
||||
selection_process2:
|
||||
Image|startswith: '\Windows\Temp\DB\\*.exe'
|
||||
Image|endswith: '\Windows\Temp\DB\\*.exe'
|
||||
selection_process3:
|
||||
CommandLine|contains: '\nslookup.exe -q=TXT'
|
||||
ParentImage|contains: '\Autoit'
|
||||
|
Loading…
Reference in New Issue
Block a user