Signature Base unknown stable yara
APT_MAL_macOS_NK_3CX_Malicious_Samples_Mar23_1 [yara]
Detects malicious macOS application related to 3CX compromise (decrypted payload)
Detection Logic
( uint16(0) == 0xfeca or uint16(0) == 0xfacf or uint32(0) == 0xbebafeca ) and all of them Field Validations
Loading…
Comments (0)
Loading comments...