Signature Base unknown stable yara
SUSP_LNX_Sindoor_ELF_Obfuscation_Aug25 [yara]
Detects ELF obfuscation technique used by Sindoor dropper related to APT 36
Detection Logic
filesize < 10MB
and uint16(0) == 0
and uint16(4) > 0
and $s1 in (0xc0..0x100) Field Validations
Loading…
Comments (0)
Loading comments...