Signature Base unknown stable yara

APT_APT29_NOBELIUM_Malware_May21_4 [yara]

Detects malware used by APT29 / NOBELIUM

View Source

Detection Logic

uint16(0) == 0x5a4d and
      filesize < 3000KB and
      ( $xc1 or 3 of them )

Field Validations

Loading…

Comments (0)

Loading comments...