Signature Base unknown stable yara
Brooxml_Phishing [yara]
Detects PDF and OOXML files leading to AiTM phishing
Detection Logic
all of ($hex*) and ((uint16be(0) == 0x504b) or (uint32be(0) == 0x25504446)) Field Validations
Loading…
Comments (0)
Loading comments...