Fixed description and title

This commit is contained in:
Florian Roth
2017-06-03 14:53:08 +02:00
parent ff5e6e3999
commit 21108e60a6
+3 -3
View File
@@ -1,6 +1,6 @@
title: Detects Fireball - archer.dll
title: Detects Fireball - Archer Install
status: experimental
description: Detects suspicious Rundll32 execution
description: Detects Archer malware invocation via rundll32
author: Florian Roth
date: 2017/06/03
reference:
@@ -13,7 +13,7 @@ detection:
selection:
EventID: 1
CommandLine: '*\rundll32.exe *,InstallArcherSvc'
condition: selection and not filter
condition: selection
falsepositives:
- Unknown
level: high