Signature Base unknown stable yara
APT_APT29_NOBELIUM_Malware_May21_4 [yara]
Detects malware used by APT29 / NOBELIUM
Detection Logic
uint16(0) == 0x5a4d and
filesize < 3000KB and
( $xc1 or 3 of them ) Field Validations
Loading…
Comments (0)
Loading comments...