rule Backdoor_Win32_Ceckno_D{ meta: description = "Backdoor:Win32/Ceckno.D,SIGNATURE_TYPE_PEHSTR,06 00 05 00 06 00 00 " strings : $a_01_0 = {53 65 72 76 69 63 65 00 38 35 37 39 46 43 35 33 44 31 37 33 35 30 39 34 43 36 32 42 43 44 38 38 43 33 33 46 32 37 42 38 } //1 敓癲捩e㔸㤷䍆㌵ㅄ㌷〵㐹㙃䈲䑃㠸㍃䘳㜲㡂 $a_01_1 = {23 31 3c 3c 3c 3c 3c 49 44 43 3c 3c 3c 3c 3c 3c 3c 3c 25 73 3c } //1 #1<<<<=5 }