From 0ffd1ef47f2e57e47bdf30c7858686ef33c08f48 Mon Sep 17 00:00:00 2001 From: Jonhnathan Date: Thu, 19 Nov 2020 23:15:38 -0300 Subject: [PATCH] Remove additional backslash --- rules/windows/malware/win_mal_ursnif.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/malware/win_mal_ursnif.yml b/rules/windows/malware/win_mal_ursnif.yml index cf696cf73..a0c51c74a 100644 --- a/rules/windows/malware/win_mal_ursnif.yml +++ b/rules/windows/malware/win_mal_ursnif.yml @@ -16,7 +16,7 @@ logsource: detection: selection: EventID: 13 - TargetObject|contains: '\Software\AppDataLow\Software\Microsoft\\' + TargetObject|contains: '\Software\AppDataLow\Software\Microsoft\' condition: selection falsepositives: - Unknown