Skip to content

Commit 9469619

Browse files
authored
Merge pull request #2737 from YungBinary/master
Rhadamanthys Yara Rule Update
2 parents c462d0b + 6ea9cca commit 9469619

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

data/yara/CAPE/Rhadamanthys.yar

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
11
rule Rhadamanthys
22
{
33
meta:
4-
author = "kevoreilly"
4+
author = "kevoreilly, YungBinary"
55
description = "Rhadamanthys Loader"
66
cape_type = "Rhadamanthys Loader"
77
strings:
88
$rc4 = {88 4C 01 08 41 81 F9 00 01 00 00 7C F3 89 75 08 33 FF 8B 4D 08 3B 4D 10 72 04 83 65 08 00}
99
$code = {8B 4D FC 3B CF 8B C1 74 0D 83 78 04 02 74 1C 8B 40 1C 3B C7 75 F3 3B CF 8B C1 74 57 83 78 04 17 74 09 8B 40 1C 3B C7 75 F3 EB}
1010
$conf = {46 BB FF 00 00 00 23 F3 0F B6 44 31 08 03 F8 23 FB 0F B6 5C 39 08 88 5C 31 08 88 44 39 08 02 C3 8B 5D 08 0F B6 C0 8A 44 08 08}
11+
$beef = {57 8D 44 33 FC 53 83 C6 FC 50 56 E8 [4] 83 C4 10 66 81 3F EF BE 0F 85}
12+
$config_2 = {0F B6 4F 2A 8D 77 2A 33 C0 6A 03 89 45 F8 89 45 FC 89 45 08 8B C1}
1113
$cape_string = "cape_options"
1214
condition:
1315
2 of them and not $cape_string

0 commit comments

Comments
 (0)