Signature Base unknown stable yara

Freeenki_Infostealer_Nov17_Export_Sig_Testing [yara]

Detects Freenki infostealer malware

View Source

Detection Logic

uint16(0) == 0x5a4d and filesize < 3000KB and
      pe.exports("getUpdate") and pe.number_of_exports == 1

Field Validations

Loading…

Comments (0)

Loading comments...