Signature Base unknown stable yara

APT12_Malware_Aug17 [yara]

Detects APT 12 Malware

View Source

Detection Logic

( uint16(0) == 0x5a4d and pe.imphash() == "9ba915fd04f248ad62e856c7238c0264" )

Field Validations

Loading…

Comments (0)

Loading comments...