SEKOIA.IO unknown stable yara
apt_sidecopy_malicious_macro [yara_rules]
Detects malicious macro used by SideCopy
Detection Logic
uint32be(0) == 0xD0CF11E0 and
all of them Field Validations
Loading…
Comments (0)
Loading comments...