Common Information
Type | Value |
---|---|
Value |
rule dragos_crashoverride_configReader { meta: description = "CRASHOVERRIDE v1 Config File Parsing" author = "Dragos Inc" strings: $s0 = { 68 E8 ?? ?? ?? 6A 00 E8 A3 ?? ?? ?? 8B F8 83 C4 ?8 } $s1 = { 8A 10 3A 11 75 ?? 84 D2 74 12 } $s2 = { 33 C0 EB ?? 1B C0 83 C8 ?? } $s3 = { 85 C0 75 ?? 8D 95 ?? ?? ?? ?? 8B CF ?? ?? } condition: all of them } |
Category | |
Type | Yara Rule |
Misp Type | |
Description |