去hybrid找了找
自带英语天赋的路过
- YARA signature "apt_duqu2_loaders" classified file "8e97c371633d285cd8fc842f4582705052a9409149ee67d97de545030787a192.bin" as "apt,duqu,duqu2" based on indicators: "530045004c0045004300540020006000440061007400610060002000460052004f004d0020006000420069006e006100720079006000200057004800450052004500200060004e0061006d00650060003d00270025007300250069002700,MSI.dll,msi.dll,StartAction"
- YARA signature "APT_Kaspersky_Duqu2_procexp" classified file "8e97c371633d285cd8fc842f4582705052a9409149ee67d97de545030787a192.bin" as "apt,duqu,duqu2" based on indicators: "7300760063006d00730069005f00330032002e0064006c006c00,MSI.dll,530045004c0045004300540020006000440061007400610060002000460052004f004d0020006000420069006e006100720079006000200057004800450052004500200060004e0061006d00650060003d00270025007300250069002700,53007900730069006e007400650072006e0061006c007300200069006e007300740061006c006c0065007200,500072006f00630065007300730020004500780070006c006f00720065007200" (Reference: https://goo.gl/7yKyOj, Author: Florian Roth)
- YARA signature "apt_duqu2_loaders" classified file "all.bstring" as "apt,duqu,duqu2" based on indicators: "SELECT `Data` FROM `Binary` WHERE `Name`='%s%i',MSI.dll,msi.dll,StartAction"
- YARA signature "APT_Kaspersky_Duqu2_procexp" classified file "all.bstring" as "apt,duqu,duqu2" based on indicators: "svcmsi_32.dll,MSI.dll,SELECT `Data` FROM `Binary` WHERE `Name`='%s%i',Sysinternals installer,Process Explorer" (Reference: https://goo.gl/7yKyOj, Author: Florian Roth)
复制代码
|