Signature Base unknown stable yara
APT_APT29_NOBELIUM_BoomBox_May21_1 [yara]
Detects BoomBox malware as described in APT29 NOBELIUM report
Detection Logic
(
uint16(0) == 0x5a4d
or 1 of ($a*)
)
and (
1 of ($x*)
or 3 of ($s*)
) Field Validations
Loading…
Comments (0)
Loading comments...