diff --git a/Exploit-Kits/BleedingLife_EK.yar b/Exploit-Kits/EK_BleedingLife.yar similarity index 94% rename from Exploit-Kits/BleedingLife_EK.yar rename to Exploit-Kits/EK_BleedingLife.yar index bea8451a..8adb14a1 100644 --- a/Exploit-Kits/BleedingLife_EK.yar +++ b/Exploit-Kits/EK_BleedingLife.yar @@ -2,7 +2,7 @@ This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license. */ -rule bleedinglife2_adobe_2010_1297_exploit +rule bleedinglife2_adobe_2010_1297_exploit : EK PDF { meta: author = "Josh Berry" @@ -33,7 +33,7 @@ strings: condition: 17 of them } -rule bleedinglife2_adobe_2010_2884_exploit +rule bleedinglife2_adobe_2010_2884_exploit : EK { meta: author = "Josh Berry" @@ -64,7 +64,7 @@ strings: condition: 17 of them } -rule bleedinglife2_jar2 +rule bleedinglife2_jar2 : EK { meta: author = "Josh Berry" @@ -87,7 +87,7 @@ strings: condition: 9 of them } -rule bleedinglife2_java_2010_0842_exploit +rule bleedinglife2_java_2010_0842_exploit : EK { meta: author = "Josh Berry"