Signature Base unknown stable yara

lnk_detect [yara]

Detects malicious LNK file from NCSC report

View Source

Detection Logic

uint32be(0) == 0x4c000000 and
      uint32be(4) == 0x01140200 and
      (($lnk_magic at 0) and $lnk_target) and 1 of ($s*)

Field Validations

Loading…

Comments (0)

Loading comments...