diff --git a/yara/gen_powershell_susp.yar b/yara/gen_powershell_susp.yar index 5e2a74a5..80e4475f 100644 --- a/yara/gen_powershell_susp.yar +++ b/yara/gen_powershell_susp.yar @@ -57,7 +57,7 @@ rule Suspicious_PowerShell_WebDownload_1 : HIGHVOL FILE { score = 60 reference = "Internal Research" date = "2017-02-22" - modified = "2022-07-27" + modified = "2024-04-03" nodeepdive = 1 id = "a763fb82-c840-531b-b631-f282bf035020" strings: @@ -77,6 +77,15 @@ rule Suspicious_PowerShell_WebDownload_1 : HIGHVOL FILE { $fp8 = "