Update win_apt_chafer_mar18.yml
This commit is contained in:
@@ -74,7 +74,8 @@ detection:
|
||||
CommandLine|startswith:
|
||||
- 'C:\wsc.exe'
|
||||
selection_process2:
|
||||
Image|endswith: '\Windows\Temp\DB\\*.exe'
|
||||
Image|contains: '\Windows\Temp\DB\'
|
||||
Image|endswith: '.exe'
|
||||
selection_process3:
|
||||
CommandLine|contains: '\nslookup.exe -q=TXT'
|
||||
ParentImage|contains: '\Autoit'
|
||||
|
||||
Reference in New Issue
Block a user