Signature Base unknown stable yara
MAL_LNX_LinaDoor_Rootkit_May22 [yara]
Detects LinaDoor Linux Rootkit
Detection Logic
uint16(0) == 0x457f and
filesize < 2000KB and 2 of them
and not 1 of ($fp*)
or 4 of them Field Validations
Loading…
Comments (0)
Loading comments...