Signature Base unknown stable yara
APT_MAL_REvil_Kaseya_Jul21_2 [yara]
Detects malware used in the Kaseya supply chain attack
Detection Logic
uint16(0) == 0x5a4d and
filesize < 3000KB and ( 2 of ($opa*) or 3 of them ) Field Validations
Loading…
Comments (0)
Loading comments...