Signature Base unknown stable yara

APT_APT29_NOBELIUM_BoomBox_May21_2 [yara]

Detects BoomBox malware used by APT29 / NOBELIUM

View Source

Detection Logic

uint16(0) == 0x5a4d and
      filesize < 40KB and
      3 of them or 4 of them

Field Validations

Loading…

Comments (0)

Loading comments...