Sneed-Reactivity/yara-mikesxrs/GoDaddy/l_exe.yara

11 lines
306 B
Text
Raw Normal View History

rule l_exe {
strings:
// 9B40C3E4B2288E29A0A15169B01F6EDE @ 0x401172
$decrypt_helper = { 8B50FC8BD98BFA8D2C8D00000000C1E704C1EB0333FB8BDAC1EB0533DD83C0FC03FB8B5C241C8BEB33E98B4C242433D103EA8B54241433FD8B68042BEF4A8968048BCD8954241475B78B7C2420 }
condition:
any of them
}