Signature Base unknown stable yara
MAL_Netfilter_May_2021_1 [yara]
Detects Netfilter rootkit
Detection Logic
uint16(0) == 0x5a4d
and filesize > 20KB and filesize < 1000KB
and (3 of ($seq*) or 2 of ($s*)) Field Validations
Loading…
Comments (0)
Loading comments...