Skip to content

Commit b4e0c8c

Browse files
authored
remove duplicate features from some rules (#984)
* remove duplicate features from some rules * keep commented hex values to show AfdOpenPacketX structure Signed-off-by: vibhatsu <[email protected]> --------- Signed-off-by: vibhatsu <[email protected]>
1 parent 7085102 commit b4e0c8c

6 files changed

+2
-7
lines changed

anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-virtualbox.yml

-1
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,6 @@ rule:
5555
- string: /\\\\.\\pipe\\VBoxTrayIPC/i
5656
- string: /VBoxTrayToolWndClass/i
5757
- string: /VBoxTrayToolWnd/i
58-
- string: /vboxservice\.exe/i
5958
- string: /vboxtray.exe/i
6059
- string: /vboxvideo/i
6160
- string: /VBoxVideoW8/i

anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-vmware.yml

-1
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,6 @@ rule:
5656
- string: /vmx86/i
5757
- string: /VMwareVMware/i
5858
- string: /vmGuestLib\.dll/i
59-
- string: /vmGuestLib\.dll/i
6059
- string: /Applications\\VMwareHostOpen\.exe/i
6160
- string: /vm3dgl\.dll/i
6261
- string: /vmdum\.dll/i

anti-analysis/anti-vm/vm-detection/reference-anti-vm-strings-targeting-xen.yml

-1
Original file line numberDiff line numberDiff line change
@@ -20,5 +20,4 @@ rule:
2020
- string: /^Xen/i
2121
- string: /XenVMMXenVMM/i
2222
- string: /xenservice.exe/i
23-
- string: /XenVMMXenVMM/i
2423
- string: /HVM domU/i

communication/socket/tcp/create-tcp-socket-via-raw-afd-driver.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ rule:
4141
- number: 0x64 = d
4242
- number: 0x4F = O
4343
- number: 0x70 = p
44-
- number: 0x65 = e
44+
# - number: 0x65 = e
4545
- number: 0x6E = n
4646
- number: 0x50 = P
4747
- number: 0x61 = a
@@ -53,7 +53,7 @@ rule:
5353
- number: 0x02
5454
- number: 0x01
5555
- number: 0x06
56-
- number: 0x00
56+
# - number: 0x00
5757
- number: 0x60
5858
- number: 0xEF
5959
- number: 0x3D

nursery/send-data-to-internet.yml

-1
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,5 @@ rule:
2424
- api: System.Net.WebClient::UploadString
2525
- api: System.Net.WebClient::UploadStringAsync
2626
- api: System.Net.WebClient::UploadStringTaskAsync
27-
- api: System.Net.WebClient::UploadValues
2827
- api: System.Net.WebClient::UploadValuesAsync
2928
- api: System.Net.WebClient::UploadValuesTaskAsync

persistence/office/act-as-office-com-add-in.yml

-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,6 @@ rule:
1919
- format: dotnet
2020
- class: Extensibility.IDTExtensibility2
2121
- or:
22-
- string: "OnAddInsUpdate"
2322
- string: "OnAddInsUpdate"
2423
- string: "OnBeginShutdown"
2524
- string: "OnConnection"

0 commit comments

Comments
 (0)