diff --git a/analyzer/windows/data/yara/DoomedLoader.yar b/analyzer/windows/data/yara/DoomedLoader.yar index 88d9e55f435..74c592a8c65 100644 --- a/analyzer/windows/data/yara/DoomedLoader.yar +++ b/analyzer/windows/data/yara/DoomedLoader.yar @@ -3,7 +3,7 @@ rule DoomedLoader meta: author = "kevoreilly" cape_options = "clear,bp0=$anti+17,action0=setzeroflag,sysbp=$syscall+7,count=0" - hash = "914b1b3180e7ec1980d0bafe6fa36daade752bb26aec572399d2f59436eaa635" + packed = "914b1b3180e7ec1980d0bafe6fa36daade752bb26aec572399d2f59436eaa635" strings: $anti = {48 8B 4C 24 ?? E8 [4] 84 C0 B8 [4] 41 0F 45 C6 EB} $syscall = {49 89 CA 8B 44 24 08 FF 64 24 10} diff --git a/data/yara/CAPE/DoomedLoader.yar b/data/yara/CAPE/DoomedLoader.yar index 46d414d52b4..6678569859a 100644 --- a/data/yara/CAPE/DoomedLoader.yar +++ b/data/yara/CAPE/DoomedLoader.yar @@ -3,7 +3,7 @@ rule DoomedLoader meta: author = "kevoreilly" cape_type = "DoomedLoader Payload" - hash = "914b1b3180e7ec1980d0bafe6fa36daade752bb26aec572399d2f59436eaa635" + packed = "914b1b3180e7ec1980d0bafe6fa36daade752bb26aec572399d2f59436eaa635" strings: $anti = {48 8B 4C 24 ?? E8 [4] 84 C0 B8 [4] 41 0F 45 C6 EB} $syscall = {49 89 CA 8B 44 24 08 FF 64 24 10}