Skip to content

Commit

Permalink
fix: FPs with rule
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed May 19, 2021
1 parent 17e262a commit 9bd583f
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion yara/apt_winnti.yar
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,7 @@ rule APT_Winnti_MAL_Dec19_1 {
$e4 = "\\BaseNamedObjects\\{B2B87CCA-66BC-4C24-89B2-C23C9EAC2A66}" wide
$e5 = "BFE_Notify_Event_{7D00FA3C-FBDC-4A8D-AEEB-3F55A4890D2A}" nocase
condition:
(any of ($e*))
uint16(0) == 0x5a4d and filesize < 3000KB and (any of ($e*))
}

rule APT_Winnti_MAL_Dec19_2 {
Expand Down

0 comments on commit 9bd583f

Please sign in to comment.