SEKOIA.IO unknown stable yara

apt_sidecopy_malicious_macro [yara_rules]

Detects malicious macro used by SideCopy

View Source

Detection Logic

uint32be(0) == 0xD0CF11E0 and
        all of them

Field Validations

Loading…

Comments (0)

Loading comments...