Signature Base unknown stable yara
Freeenki_Infostealer_Nov17_Export_Sig_Testing [yara]
Detects Freenki infostealer malware
Detection Logic
uint16(0) == 0x5a4d and filesize < 3000KB and
pe.exports("getUpdate") and pe.number_of_exports == 1 Field Validations
Loading…
Comments (0)
Loading comments...