diff --git a/malware/Gholee.yar b/malware/Gholee.yar index 41269008..cd36d003 100644 --- a/malware/Gholee.yar +++ b/malware/Gholee.yar @@ -56,16 +56,16 @@ rule gholeeV2 rule MW_gholee_v1 : v1 { meta: - author = “@GelosSnake” + Author = "@GelosSnake" description = "http://securityaffairs.co/wordpress/28170/cyber-crime/gholee-malware.html" - date = “2014-08″ - maltype = “Remote Access Trojan” - sample_filetype = “dll” + date = "2014-08" + maltype = "Remote Access Trojan" + sample_filetype = "dll" hash0 = "48573a150562c57742230583456b4c02" strings: - $a = “sandbox_avg10_vc9_SP1_2011″ - $b = “gholee” + $a = "sandbox_avg10_vc9_SP1_2011" + $b = "gholee" condition: all of them