Question: Example signatures: rule Malware _ 1 { strings: $s 1 = SystemRoot System 3 2 hal . dll
Example signatures:
rule Malware
strings:
$sSystemRootSystemhaldll fullword wide
$shttp:wwwjmicron.cotw fullword ascii
condition:
uintxad and filesize KB and all of them
rule Malware
strings:
$xobjfrewkxiguavapdb ascii
$xMRxClssys fullword wide
$x "MRXNET.Sys fullword wide
condition:
uintxad and filesize KB and of them
rule Malware
strings:
$sSystemRootSystemhaldll fullword wide
$sobjfrewkxiguavapdb ascii
$shttp:wwwjmicron.cotw fullword ascii
$sMRxClssys fullword wide
$s "MRXNET.Sys fullword wide
condition:
uintxad and filesize KB and of them
Which rule name in the description above has the lowest chance of a false positive?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
