YARA unknown stable yara
apt_hiddencobra_binaries [malware]
HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure
Detection Logic
(uint16(0) == 0x5A4D or uint16(0) == 0xCFD0 or uint16(0) == 0xC3D4 or uint32(0) == 0x46445025 or uint32(1) == 0x6674725C) and 2 of them Field Validations
Loading…
Comments (0)
Loading comments...