Skip to content

Commit ba20b04

Browse files
committed
Tighten FormhookB monitor yara (again!) - fixes #2648
1 parent b4124a5 commit ba20b04

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

analyzer/windows/data/yara/Formbook.yar

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ rule FormhookB
2626
$new_remap = {8B (86 [2] 00 00|46 ??|06) 5F 5E 5B 8B E5 5D C3}
2727
$code = {8B 4E 18 50 6A 00 51 57 56 E8 9A 18 00 00 8B 55 10 8B 45 0C 8B 0F 83 C4 1C 52 50 FF D1 5F 5E 5D C3}
2828
condition:
29-
any of them
29+
2 of them
3030
}
3131

3232
rule FormconfA

0 commit comments

Comments
 (0)