import "pe" rule W32ChirB_eml { meta: description = "readme.eml - Chir.B" author = "wit0k" reference = "" date = "2018-08-30" hash1 = "d41a5c4fe5171cbfe26ef04da347188d1c22e34d2d4cdffd833f38d61e3b6ec8" strings: $s4 = "
" fullword ascii $s6 = "UAToCwAAAGCJGIlQBPzzpGHP+maPAGaPQAaLdQiLfQyLTRDM+2HJwgwA6cgAAABgi0UIagBQUGoA/5aQAAAAYcnCBAAAAAAAAAAAAMMAAAAAAAAAAAAAAAAAAAA=" fullword ascii $s7 = /FROM: .{1,20}@yahoo\.com/ fullword ascii nocase $s8 = /Content-Type: audio\/x-wav; name=.{1,20}.exe/ fullword ascii nocase $s11 = "dmFTY3JpcHQiPndpbmRvdy5vcGVuKCJyZWFkbWUuZW1sIiwgbnVsbCwicmVzaXphYmxlPW5vLHRvcD02MDAwLGxlZnQ9NjAwMCIpPC9zY3JpcHQ+PC9odG1sPgBYanhQ" ascii /* base64 encoded string 'vaScript">window.open("readme.eml", null,"resizable=no,top=6000,left=6000")