前期准备010editor,winhex,notepad;xmrig样本
rule xmrig_wk_virus
{
meta:
description = "xmrig挖矿病毒"
in_the_wild = true
threat_level = 7
tag = "xmrig_wk_virus"
author = "@"
hide = true
strings:
$hex = {4D 5A}
$a = "stratum"
$b = "xmrig"
$c = "pool"
condition:
($hex or $a or $b or $c) or (all of them)
}