Signature Base unknown stable yara

SUSP_ZIP_ISO_PhishAttachment_Pattern_Jun22_1 [yara]

Detects suspicious small base64 encoded ZIP files (MIME email attachments) with .iso files as content as often used in phishing attacks

View Source

Detection Logic

filesize < 2000KB and 1 of ($pk*) and 1 of ($iso*)

Field Validations

Loading…

Comments (0)

Loading comments...