OSX Keranger detection fix

This commit is contained in:
Javier Marcos 2016-03-07 09:25:32 -08:00
parent 677c448dea
commit 7c18ce9bb0

View File

@ -202,7 +202,7 @@
"value": "Artifact used by this malware"
},
"Keranger_2": {
"query": "select * from file where path like '/Users/%/Library/.kernel_%' or path like '/Users/%/Library/kernel_service';",
"query": "select * from file where path like '/Users/%/Library/.kernel_%' union select * from file where path like '/Users/%/Library/kernel_service';",
"interval": "86400",
"description": "http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/",
"value": "Artifact used by this malware"