ReversingLabs unknown stable yara
Win32_Virus_Negt [virus]
Yara rule that detects Negt virus.
Detection Logic
uint16(0) == 0x5A4D and
(($negt_infector at pe.entry_point) or
(($negt_body_and_infector_1 at pe.entry_point) and $negt_body_and_infector_2 and
$negt_body_and_infector_3 and $negt_body_and_infector_4)) Field Validations
Loading…
Comments (0)
Loading comments...