ReversingLabs unknown stable yara

Win32_Virus_Awfull [virus]

Yara rule that detects Awfull virus.

View Source

Detection Logic

uint16(0) == 0x5A4D and 
        ($awfull_body at pe.entry_point)

Field Validations

Loading…

Comments (0)

Loading comments...