08e8d462fe
RED PILL 🔴 💊
13 lines
265 B
Text
13 lines
265 B
Text
rule antivirusdetector
|
|
{
|
|
meta:
|
|
reference = "https://cdn2.hubspot.net/hubfs/270968/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf"
|
|
|
|
strings:
|
|
$s1 = "getShadyProcess"
|
|
$s2 = "getSystemAntiviruses"
|
|
$s3 = "AntiVirusDetector"
|
|
|
|
condition:
|
|
all of them
|
|
}
|