Signature Base unknown stable yara

APT_MAL_NK_3CX_macOS_Elextron_App_Mar23_1 [yara]

Detects macOS malware used in the 3CX incident

View Source

Detection Logic

uint16(0) == 0xfacf and
      filesize < 400KB and (
         all of ($a*) 
         and 1 of ($s*)
      )

Field Validations

Loading…

Comments (0)

Loading comments...