rule: added Emotet UA

https://twitter.com/webbthewombat/status/1225827092132179968
This commit is contained in:
Florian Roth 2020-02-08 10:37:56 +01:00
parent be9b80d6ab
commit d9645af840

View File

@ -56,6 +56,8 @@ detection:
# Ursnif
- 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)'
- 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)'
# Emotet
- 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)' # https://twitter.com/webbthewombat/status/1225827092132179968
# Others
- '* pxyscand*'
- '* asd'