Signature Base unknown stable yara

Saudi_Phish_Trojan [yara]

Detects a trojan used in Saudi Aramco Phishing

View Source

Detection Logic

( uint16(0) == 0x5a4d and filesize < 3000KB and 1 of them )

Field Validations

Loading…

Comments (0)

Loading comments...