There is no description at this point.
rule win_xenorat_w0 { meta: author = "jeFF0Falltrades" date = "2024-07-30" version = "1" description = "Detects win.xenorat." malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xenorat" malpedia_rule_date = "20240730" malpedia_hash = "" malpedia_version = "20240730" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $str_xeno_rat_1 = "xeno rat" wide ascii nocase $str_xeno_rat_2 = "xeno_rat" wide ascii nocase $str_xeno_update_mgr = "XenoUpdateManager" wide ascii $str_nothingset = "nothingset" wide ascii $byte_enc_dec_pre = { 1f 10 8d [4] (0a | 0b) } $patt_config = { 72 [3] 70 80 [3] 04 } condition: 4 of them and #patt_config >= 5 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY