Signature Base unknown stable yara

Brooxml_Phishing [yara]

Detects PDF and OOXML files leading to AiTM phishing

View Source

Detection Logic

all of ($hex*) and ((uint16be(0) == 0x504b) or (uint32be(0) == 0x25504446))

Field Validations

Loading…

Comments (0)

Loading comments...