diff --git a/data/yara/CAPE/DCRat.yar b/data/yara/CAPE/DCRat.yar index 7e195d0a..ac66b917 100644 --- a/data/yara/CAPE/DCRat.yar +++ b/data/yara/CAPE/DCRat.yar @@ -68,7 +68,7 @@ rule DCRat { rule dcrat_kingrat { meta: author = "jeFF0Falltrades" - cape_type = "DCRat Payload" + cape_type = "DCRat Payload" strings: $venom_1 = "VenomRAT" wide ascii nocase diff --git a/data/yara/CAPE/QuasarRAT.yar b/data/yara/CAPE/QuasarRAT.yar index 360a16d2..1112b8d9 100644 --- a/data/yara/CAPE/QuasarRAT.yar +++ b/data/yara/CAPE/QuasarRAT.yar @@ -24,13 +24,13 @@ rule QuasarRAT { rule quasarrat_kingrat { meta: author = "jeFF0Falltrades" - cape_type = "Quasarrat Payload" + cape_type = "Quasarrat Payload" strings: $str_quasar = "Quasar." wide ascii $str_hidden = "set_Hidden" wide ascii $str_shell = "DoShellExecuteResponse" wide ascii - $str_close = "echo DONT CLOSE THIS WINDOW!" wide ascii + $str_close = "echo DONT CLOSE THIS WINDOW!" wide ascii $str_pause = "ping -n 10 localhost > nul" wide ascii $str_aes_exc = "masterKey can not be null or empty" wide ascii $byte_aes_key_base = { 7E [3] 04 73 [3] 06 25 }