Skip to content

Commit ccb8a64

Browse files
committed
Fixed FP for Emotet yara rule #17
1 parent 3741319 commit ccb8a64

File tree

2 files changed

+4
-6
lines changed

2 files changed

+4
-6
lines changed

utils/emotetscan.py

+2-3
Original file line numberDiff line numberDiff line change
@@ -36,12 +36,11 @@
3636
strings: \
3737
$v4a = { BB 00 C3 4C 84 } \
3838
$v4b = { B8 00 C3 CC 84 } \
39-
$v5a = { 69 01 6D 4E C6 41 05 39 30 00 00} \
40-
$v5b = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 } \
39+
$v5a = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 } \
4140
$v6a = { C7 40 20 ?? ?? ?? 00 C7 40 10 ?? ?? ?? 00 C7 40 0C 00 00 00 00 83 3C CD ?? ?? ?? ?? 00 74 0E 41 89 48 ?? 83 3C CD ?? ?? ?? ?? 00 75 F2 } \
4241
$v7a = { 6A 06 33 D2 ?? F7 ?? 8B DA 43 74 } \
4342
$v7b = { 83 E6 0F 8B CF 83 C6 04 50 8B D6 E8 ?? ?? ?? ?? 59 6A 2F 8D 3C 77 58 66 89 07 83 C7 02 4B 75 } \
44-
condition: all of ($v4*) or $v5a or $v5b or $v6a or all of ($v7*)}'
43+
condition: all of ($v4*) or $v5a or $v6a or all of ($v7*)}'
4544
}
4645

4746
# MZ Header

yara/rule.yara

+2-3
Original file line numberDiff line numberDiff line change
@@ -167,13 +167,12 @@ rule Emotet {
167167
strings:
168168
$v4a = { BB 00 C3 4C 84 }
169169
$v4b = { B8 00 C3 CC 84 }
170-
$v5a = { 69 01 6D 4E C6 41 05 39 30 00 00 }
171-
$v5b = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 }
170+
$v5a = { 6D 4E C6 41 33 D2 81 C1 39 30 00 00 }
172171
$v6a = { C7 40 20 ?? ?? ?? 00 C7 40 10 ?? ?? ?? 00 C7 40 0C 00 00 00 00 83 3C CD ?? ?? ?? ?? 00 74 0E 41 89 48 ?? 83 3C CD ?? ?? ?? ?? 00 75 F2 }
173172
$v7a = { 6A 06 33 D2 ?? F7 ?? 8B DA 43 74 }
174173
$v7b = { 83 E6 0F 8B CF 83 C6 04 50 8B D6 E8 ?? ?? ?? ?? 59 6A 2F 8D 3C 77 58 66 89 07 83 C7 02 4B 75 }
175174
176-
condition: all of ($v4*) or $v5a or $v5b or $v6a or all of ($v7*)
175+
condition: all of ($v4*) or $v5a or $v6a or all of ($v7*)
177176
}
178177

179178
rule SmokeLoader {

0 commit comments

Comments
 (0)