Update win_apt_chafer_mar18.yml

This commit is contained in:
Jonhnathan
2020-10-27 23:28:04 -03:00
committed by GitHub
parent 0860978412
commit 28febe5dd2
@@ -74,7 +74,8 @@ detection:
CommandLine|startswith:
- 'C:\wsc.exe'
selection_process2:
Image|endswith: '\Windows\Temp\DB\\*.exe'
Image|contains: '\Windows\Temp\DB\'
Image|endswith: '.exe'
selection_process3:
CommandLine|contains: '\nslookup.exe -q=TXT'
ParentImage|contains: '\Autoit'