From 3c44582ec6d0926c70041b5b070a97f371170f54 Mon Sep 17 00:00:00 2001 From: blackorbird <137812951@qq.com> Date: Wed, 3 Apr 2019 22:36:28 +0800 Subject: [PATCH] Create hunting-rule.txt --- Oceanlotus/hunting-rule.txt | 2 ++ 1 file changed, 2 insertions(+) create mode 100644 Oceanlotus/hunting-rule.txt diff --git a/Oceanlotus/hunting-rule.txt b/Oceanlotus/hunting-rule.txt new file mode 100644 index 0000000..90a1c33 --- /dev/null +++ b/Oceanlotus/hunting-rule.txt @@ -0,0 +1,2 @@ +imports:”GdipGetImageWidth” AND imports:”WriteProcessMemory” AND imports:”GdipCreateBitmapFromFile” +AND tag:pedll