Isarcextract Dll !link! Download -
rule isarcextract_malicious strings: $s1 = "cmd.exe /c" wide ascii $s2 = "http://" ascii condition: (uint16(0) == 0x5A4D) and ($s1 or $s2)
rule isarcextract_malicious strings: $s1 = "cmd.exe /c" wide ascii $s2 = "http://" ascii condition: (uint16(0) == 0x5A4D) and ($s1 or $s2)

MA. Cry of Silence