Signature Base unknown stable yara

SUSP_LNX_Sindoor_ELF_Obfuscation_Aug25 [yara]

Detects ELF obfuscation technique used by Sindoor dropper related to APT 36

View Source

Detection Logic

filesize < 10MB
      and uint16(0) == 0
      and uint16(4) > 0
      and $s1 in (0xc0..0x100)

Field Validations

Loading…

Comments (0)

Loading comments...