ReversingLabs unknown stable yara
Win32_Ransomware_Archiveus [ransomware]
Yara rule that detects Archiveus ransomware.
Detection Logic
uint16(0) == 0x5A4D and ($entry_point at pe.entry_point) and $dump_instruction and $extension_rule and $instruction_string Field Validations
Loading…
Comments (0)
Loading comments...