ReversingLabs unknown stable yara

Win32_Ransomware_Archiveus [ransomware]

Yara rule that detects Archiveus ransomware.

View Source

Detection Logic

uint16(0) == 0x5A4D and ($entry_point at pe.entry_point) and $dump_instruction and $extension_rule and $instruction_string

Field Validations

Loading…

Comments (0)

Loading comments...