Skip to content

Commit

Permalink
Update mal_sophos_pygmy_nov24.yar
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Nov 4, 2024
1 parent 875c757 commit 30b0714
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions yara/mal_sophos_pygmy_nov24.yar
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,8 @@ rule MAL_Sophos_XG_Pygmy_Goat_AES_Key {
$dword_8 = { 55 51 50 77 }
condition:
uint32(0) == 0x464c457f and all of them
// due to FPs - but I don't know the file size of the implant
and filesize < 4MB
}

rule MAL_Sophos_XG_Pygmy_Goat_Magic_Strings {
Expand Down

0 comments on commit 30b0714

Please sign in to comment.