Signature Base unknown stable yara

Freeenki_Infostealer_Nov17 [yara]

Detects Freenki infostealer malware

View Source

Detection Logic

uint16(0) == 0x5a4d and filesize < 3000KB and (
        1 of ($x*) or
        3 of them or
        all of ($a*)
      )

Field Validations

Loading…

Comments (0)

Loading comments...