Signature Base unknown stable yara

APT_APT29_NOBELIUM_BoomBox_May21_1 [yara]

Detects BoomBox malware as described in APT29 NOBELIUM report

View Source

Detection Logic

( 
         uint16(0) == 0x5a4d 
         or 1 of ($a*) 
      )
      and (
         1 of ($x*)
         or 3 of ($s*)
      )

Field Validations

Loading…

Comments (0)

Loading comments...