Signature Base unknown stable yara

APT_MAL_REvil_Kaseya_Jul21_1 [yara]

Detects malware used in the Kaseya supply chain attack

View Source

Detection Logic

uint16(0) == 0x5a4d and
      filesize < 3000KB and
      (
         pe.imphash() == "c36dcd2277c4a707a1a645d0f727542a" or
         2 of them
      )

Field Validations

Loading…

Comments (0)

Loading comments...