File tree Expand file tree Collapse file tree 2 files changed +8
-8
lines changed
third_party/yara/bartblaze Expand file tree Collapse file tree 2 files changed +8
-8
lines changed Original file line number Diff line number Diff line change @@ -5,7 +5,7 @@ rule Autumn_Backdoor_Loader
55 fingerprint = " v1_sha256_09a399531a2e2f8064b1c9862949fa1c9eca1ddab19bfb62a5ce947e002445cc "
66 version = " 1.0 "
77 date = " 2025-11-18 "
8- modified = " 2025-11-18 "
8+ modified = " 2025-11-20 "
99 status = " RELEASED "
1010 sharing = " TLP:CLEAR "
1111 source = " BARTBLAZE "
@@ -14,14 +14,14 @@ rule Autumn_Backdoor_Loader
1414 category = " MALWARE "
1515 malware = " UNKNOWN "
1616 malware_type = " BACKDOOR "
17- reference = " https://malpedia.caad.fkie.fraunhofer.de/details/win.broomstick "
17+ reference = " https://cyberarmor.tech/blog/autumn-dragon-china-nexus-apt-group-targets-south-east-asia "
1818 hash = " 843fca1cf30c74edd96e7320576db5a39ebf8d0a708bde8ccfb7c12e45a7938c "
1919 hash = " d7711333c34a27aed5d38755f30d14591c147680e2b05eaa0484c958ddaae3b6 "
2020
21- strings :
22- $ pdb_dev = " \\ Dev \\ ApplicationDllHijacking \\ "
23- $ pdb_user = " \\ Users \\ LG02 \\ Desktop \\ ??? \\ "
21+ strings :
22+ $ pdb_dev = " \\ Dev \\ ApplicationDllHijacking \\ "
23+ $ pdb_user = " \\ Users \\ LG02 \\ Desktop \\ ??? \\ "
2424
25- condition :
26- any of them
25+ condition :
26+ any of them
2727 }
Original file line number Diff line number Diff line change 1- cce2b61fa7f71aca33a207d52b4d4c84028754fb
1+ 1eb421e2de322161c9930a415ec8fa340dbeaf68
You can’t perform that action at this time.
0 commit comments