From d331e7ee3c1e7605d7941cf193663fa85114f469 Mon Sep 17 00:00:00 2001 From: Bart P <3075118+bartblaze@users.noreply.github.com> Date: Tue, 13 Aug 2024 16:16:47 +0200 Subject: [PATCH] Update RedLine.yar --- rules/crimeware/RedLine.yar | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/rules/crimeware/RedLine.yar b/rules/crimeware/RedLine.yar index f245c73..479af91 100644 --- a/rules/crimeware/RedLine.yar +++ b/rules/crimeware/RedLine.yar @@ -14,7 +14,7 @@ rule RedLine_a description = "Identifies RedLine stealer." category = "MALWARE" malware = "REDLINE" - malware = "INFOSTEALER" + malware_type = "INFOSTEALER" strings: $ = "Account" ascii wide @@ -101,6 +101,8 @@ rule RedLine_b author = "@bartblaze" description = "Identifies RedLine stealer." category = "MALWARE" + malware = "REDLINE" + malware_type = "INFOSTEALER" strings: $ = "Account" ascii wide