Common Information
Type Value
Value
rule dragos_crashoverride_configReader {
	meta:
		description = "CRASHOVERRIDE v1 Config File Parsing"
		author = "Dragos Inc"
	strings:
		$s0 = { 68 E8 ?? ?? ?? 6A 00 E8 A3 ?? ?? ?? 8B F8 83 C4 ?8 }
		$s1 = { 8A 10 3A 11 75 ?? 84 D2 74 12 }
		$s2 = { 33 C0 EB ?? 1B C0 83 C8 ?? }
		$s3 = { 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 8B CF ?? ?? }
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2017-06-12 37 CrashOverride Malware | CISA