mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_malware_emotet.yml
This commit is contained in:
parent
035cd43e58
commit
d962e5b844
@ -21,15 +21,15 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
- '* -e* PAA*'
|
||||
- '*JABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQ*' # $env:userprofile
|
||||
- '*QAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUA*' # $env:userprofile
|
||||
- '*kAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlA*' # $env:userprofile
|
||||
- '*IgAoACcAKgAnACkAOwAkA*' # "('*');$
|
||||
- '*IAKAAnACoAJwApADsAJA*' # "('*');$
|
||||
- '*iACgAJwAqACcAKQA7ACQA*' # "('*');$
|
||||
- '*JABGAGwAeAByAGgAYwBmAGQ*'
|
||||
CommandLine|contains:
|
||||
- ' -e* PAA'
|
||||
- 'JABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQ' # $env:userprofile
|
||||
- 'QAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUA' # $env:userprofile
|
||||
- 'kAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlA' # $env:userprofile
|
||||
- 'IgAoACcAKgAnACkAOwAkA' # "('*');$
|
||||
- 'IAKAAnACoAJwApADsAJA' # "('*');$
|
||||
- 'iACgAJwAqACcAKQA7ACQA' # "('*');$
|
||||
- 'JABGAGwAeAByAGgAYwBmAGQ'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
Loading…
Reference in New Issue
Block a user