Merge pull request #306 from tstromberg/apt36-desktop
Improve base64/crontab detection
This commit is contained in:
commit
e97f2fd344
|
@ -129,6 +129,8 @@ WHERE
|
||||||
OR p0_cmd LIKE '%rm -rf /boot%'
|
OR p0_cmd LIKE '%rm -rf /boot%'
|
||||||
OR p0_cmd LIKE '%nohup /bin/bash%'
|
OR p0_cmd LIKE '%nohup /bin/bash%'
|
||||||
OR p0_cmd LIKE '%echo%|%base64 --decode %|%'
|
OR p0_cmd LIKE '%echo%|%base64 --decode %|%'
|
||||||
|
OR p0_cmd LIKE '%echo%|%base64 -d %|%'
|
||||||
|
OR p0_cmd LIKE '%@reboot%crontab%'
|
||||||
OR p0_cmd LIKE '%UserKnownHostsFile=/dev/null%' -- Crypto miners
|
OR p0_cmd LIKE '%UserKnownHostsFile=/dev/null%' -- Crypto miners
|
||||||
OR p0_cmd LIKE '%monero%'
|
OR p0_cmd LIKE '%monero%'
|
||||||
OR p0_cmd LIKE '%nanopool%'
|
OR p0_cmd LIKE '%nanopool%'
|
||||||
|
|
|
@ -128,6 +128,7 @@ WHERE
|
||||||
AND p0_cmd NOT LIKE '% history'
|
AND p0_cmd NOT LIKE '% history'
|
||||||
)
|
)
|
||||||
OR p0_cmd LIKE '%echo%|%base64 --decode %|%'
|
OR p0_cmd LIKE '%echo%|%base64 --decode %|%'
|
||||||
|
OR p0_cmd LIKE '%echo%|%base64 -d %|%'
|
||||||
OR p0_cmd LIKE '%launchctl bootout%'
|
OR p0_cmd LIKE '%launchctl bootout%'
|
||||||
OR p0_cmd LIKE '%chflags uchg%'
|
OR p0_cmd LIKE '%chflags uchg%'
|
||||||
OR (
|
OR (
|
||||||
|
|
Loading…
Reference in New Issue