diff --git a/rules/crimeware/RedLine.yar b/rules/crimeware/RedLine.yar index f245c73..479af91 100644 --- a/rules/crimeware/RedLine.yar +++ b/rules/crimeware/RedLine.yar @@ -14,7 +14,7 @@ rule RedLine_a description = "Identifies RedLine stealer." category = "MALWARE" malware = "REDLINE" - malware = "INFOSTEALER" + malware_type = "INFOSTEALER" strings: $ = "Account" ascii wide @@ -101,6 +101,8 @@ rule RedLine_b author = "@bartblaze" description = "Identifies RedLine stealer." category = "MALWARE" + malware = "REDLINE" + malware_type = "INFOSTEALER" strings: $ = "Account" ascii wide