Context
970307708071c01d32ef542a49099571852846a980d6e8eb164d2578147a1628
01fd153bfb4be440dd46cea7bebe8eb61b1897596523f6f6d1a507a708b17cc7
0x8eac3198dd72f3e07108c4c7cff43108ad48a71c
0x9bc1355344b54dedf3e44296916ed15653844509
0x86d1a21fd151e344ccc0778fd018c281db9d40b6ccd4bdd3588cb40fade1a33a
0xc2da361c40279a4f2f84448791377652f2bf41f06d18f19941a96c720228cd0f
0xf9d432745ea15dbc00ff319417af3763f72fcf8a4debedbfceeef4246847ce41
rule G_Downloader_JADESNOW_1 { meta: author = "Google Threat Intelligence Group (GTIG)" strings: $s1 = "global['_V']" $s2 = "global['r']" $s3 = "umP" $s4 = "mergeConfig" $s5 = "charAt" nocase condition: uint16(0) != 0x5A4D and filesize < 10KB and #s3 > 2 and #s5 == 1 and all of them }