Skip to content

Commit

Permalink
(osquery#3500) Add Check for Additional Leverage Variant
Browse files Browse the repository at this point in the history
  • Loading branch information
clong authored and obelisk committed Jul 31, 2017
1 parent 383a39b commit be1a943
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions packs/osx-attacks.conf
Expand Up @@ -28,6 +28,13 @@
"description" : "(http://www.intego.com/mac-security-blog/new-mac-trojan-discovered-related-to-syria/)",
"value" : "Artifact used by this malware"
},
"Leverage-A_3": {
"query" : "select * from launchd where name = 'com.GetFlashPlayer.plist';",
"interval" : "3600",
"version": "1.4.5",
"description" : "(https://www.volexity.com/blog/2017/07/24/real-news-fake-flash-mac-os-x-users-targeted/)",
"value" : "Artifact used by this malware"
},
"Tibet.D": {
"query" : "select * from launchd where path like '%com.apple.AudioService.plist';",
"interval" : "3600",
Expand Down

0 comments on commit be1a943

Please sign in to comment.