Signature Base unknown stable yara
APT_MAL_REvil_Kaseya_Jul21_1 [yara]
Detects malware used in the Kaseya supply chain attack
Detection Logic
uint16(0) == 0x5a4d and
filesize < 3000KB and
(
pe.imphash() == "c36dcd2277c4a707a1a645d0f727542a" or
2 of them
) Field Validations
Loading…
Comments (0)
Loading comments...