Signature Base unknown stable yara
APT_APT29_NOBELIUM_BoomBox_May21_2 [yara]
Detects BoomBox malware used by APT29 / NOBELIUM
Detection Logic
uint16(0) == 0x5a4d and
filesize < 40KB and
3 of them or 4 of them Field Validations
Loading…
Comments (0)
Loading comments...