Signature Base unknown stable yara
Winnti_malware_Nsiproxy [yara]
Detects a Winnti rootkit
Detection Logic
uint16(0) == 0x5a4d and $x1 and 1 of ($a*) and 2 of ($s*) Field Validations
Loading…
Comments (0)
Loading comments...
Detects a Winnti rootkit
uint16(0) == 0x5a4d and $x1 and 1 of ($a*) and 2 of ($s*) Loading…
Loading comments...