Update win_malware_emotet.yml

This commit is contained in:
Jonhnathan 2020-10-15 18:01:00 -03:00 committed by GitHub
parent 035cd43e58
commit d962e5b844
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -21,15 +21,15 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- '* -e* PAA*'
- '*JABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQ*' # $env:userprofile
- '*QAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUA*' # $env:userprofile
- '*kAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlA*' # $env:userprofile
- '*IgAoACcAKgAnACkAOwAkA*' # "('*');$
- '*IAKAAnACoAJwApADsAJA*' # "('*');$
- '*iACgAJwAqACcAKQA7ACQA*' # "('*');$
- '*JABGAGwAeAByAGgAYwBmAGQ*'
CommandLine|contains:
- ' -e* PAA'
- 'JABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQ' # $env:userprofile
- 'QAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUA' # $env:userprofile
- 'kAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlA' # $env:userprofile
- 'IgAoACcAKgAnACkAOwAkA' # "('*');$
- 'IAKAAnACoAJwApADsAJA' # "('*');$
- 'iACgAJwAqACcAKQA7ACQA' # "('*');$
- 'JABGAGwAeAByAGgAYwBmAGQ'
condition: selection
fields:
- CommandLine