Signature Base unknown stable yara

MAL_LNX_LinaDoor_Rootkit_May22 [yara]

Detects LinaDoor Linux Rootkit

View Source

Detection Logic

uint16(0) == 0x457f and
      filesize < 2000KB and 2 of them 
      and not 1 of ($fp*)
      or 4 of them

Field Validations

Loading…

Comments (0)

Loading comments...