diff --git a/signatures/common.yara b/signatures/common.yara index 9b51fb5..9c7370d 100644 --- a/signatures/common.yara +++ b/signatures/common.yara @@ -15,6 +15,9 @@ rule CHINESE_NEZHA_ARGO { $a13 = "Server\x20is\x20running\x20on\x20port\x20" $a14 = "nysteria2" $a15 = "openssl req" + $a16 = "hysteria2" + $a17 = "NEZHA" nocase + $a18 = "babama1001980" condition: 2 of ($a*) }