Skip to content

Commit 9d4977f

Browse files
committed
YungBinary: Update Amadey Rule
1 parent b2736e3 commit 9d4977f

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

data/yara/CAPE/Amadey.yar

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,15 @@
11
rule Amadey
22
{
33
meta:
4-
author = "kevoreilly"
4+
author = "kevoreilly, YungBinary"
55
description = "Amadey Payload"
66
cape_type = "Amadey Payload"
77
hash = "988258716d5296c1323303e8fe4efd7f4642c87bfdbe970fe9a3bb3f410f70a4"
88
strings:
99
$decode1 = {8B D1 B8 FF FF FF 7F D1 EA 2B C2 3B C8 76 07 BB FF FF FF 7F EB 08 8D 04 0A 3B D8 0F 42 D8}
10-
$decode2 = {33 D2 8B 4D ?? 8B C7 F7 F6 8A 84 3B [4] 2A 44 0A 01 88 87 [4] 47 8B 45 ?? 8D 50 01}
11-
$decode3 = {8A 04 02 88 04 0F 41 8B 7D ?? 8D 42 01 3B CB 7C}
10+
$decode2 = {2B C8 8D 04 0A 33 D2 F7 F3 8B 5D ?? 8B CB 83 7B ?? 10}
11+
$decode3 = {33 D2 8B 4D ?? 8B C7 F7 F6 8A 84 3B [4] 2A 44 0A 01 88 87 [4] 47 8B 45 ?? 8D 50 01}
12+
$decode4 = {8A 04 02 88 04 0F 41 8B 7D ?? 8D 42 01 3B CB 7C}
1213
condition:
1314
uint16(0) == 0x5A4D and 2 of them
1415
}

0 commit comments

Comments
 (0)