Signature Base unknown stable yara
APT_MAL_NK_3CX_macOS_Elextron_App_Mar23_1 [yara]
Detects macOS malware used in the 3CX incident
Detection Logic
uint16(0) == 0xfacf and
filesize < 400KB and (
all of ($a*)
and 1 of ($s*)
) Field Validations
Loading…
Comments (0)
Loading comments...