Common Information
Type | Value |
---|---|
Value |
rule BLACKMOON_BANKER { meta: author = "Proofpoint Staff" info = "blackmoon update" strings: $s1 = "BlackMoon RunTime Error:" ascii wide nocase $s2 = "\\system32\\rundll32.exe" ascii wide $s3 = "cmd.exe /c ipconfig /flushdns" ascii wide $s4 = "\\system32\\drivers\\etc\\hosts.ics" ascii wide condition: all of them } |
Category | |
Type | Yara Rule |
Misp Type | |
Description |