mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 09:25:17 +00:00
rule: added Emotet UA
https://twitter.com/webbthewombat/status/1225827092132179968
This commit is contained in:
parent
be9b80d6ab
commit
d9645af840
@ -56,6 +56,8 @@ detection:
|
||||
# Ursnif
|
||||
- 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)'
|
||||
- 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)'
|
||||
# Emotet
|
||||
- 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)' # https://twitter.com/webbthewombat/status/1225827092132179968
|
||||
# Others
|
||||
- '* pxyscand*'
|
||||
- '* asd'
|
||||
|
Loading…
Reference in New Issue
Block a user