Signature Base unknown stable yara

APT_MAL_macOS_NK_3CX_Malicious_Samples_Mar23_1 [yara]

Detects malicious macOS application related to 3CX compromise (decrypted payload)

View Source

Detection Logic

( uint16(0) == 0xfeca or uint16(0) == 0xfacf or uint32(0) == 0xbebafeca ) and all of them

Field Validations

Loading…

Comments (0)

Loading comments...