File tree Expand file tree Collapse file tree 1 file changed +2
-4
lines changed Expand file tree Collapse file tree 1 file changed +2
-4
lines changed Original file line number Diff line number Diff line change 1- import " pe "
2-
31rule SUSP_LNX_Sindoor_ELF_Obfuscation_Aug25 {
42 meta :
53 description = " Detects ELF obfuscation technique used by Sindoor dropper related to APT 36 "
@@ -52,7 +50,7 @@ rule MAL_Sindoor_Decryptor_Aug25 {
5250 condition :
5351 filesize < 100MB
5452 and (
55- uint16 (0 ) == 0x5a4d // Windows
53+ uint16 (0 ) == 0x5a4d // Windows
5654 or uint32be (0 ) == 0x7f454c46 // Linux
5755 or (uint32be (0 ) == 0xcafebabe and uint32be (4 ) < 0x20 ) // Universal mach-O App with dont-match-java-class-file hack
5856 or uint32 (0 ) == 0xfeedface // 32-bit mach-O
@@ -78,7 +76,7 @@ rule MAL_Sindoor_Downloader_Aug25 {
7876 condition :
7977 filesize < 100MB
8078 and (
81- uint16 (0 ) == 0x5a4d // Windows
79+ uint16 (0 ) == 0x5a4d // Windows
8280 or uint32be (0 ) == 0x7f454c46 // Linux
8381 or (uint32be (0 ) == 0xcafebabe and uint32be (4 ) < 0x20 ) // Universal mach-O App with dont-match-java-class-file hack
8482 or uint32 (0 ) == 0xfeedface // 32-bit mach-O
You can’t perform that action at this time.
0 commit comments