YARA unknown stable yara

apt_hiddencobra_binaries [malware]

HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure

View Source

Detection Logic

(uint16(0) == 0x5A4D or uint16(0) == 0xCFD0 or uint16(0) == 0xC3D4 or uint32(0) == 0x46445025 or uint32(1) == 0x6674725C) and 2 of them

Field Validations

Loading…

Comments (0)

Loading comments...