YARA unknown stable yara
apt_ProjectSauron_encrypted_LSA [malware]
Rule to detect ProjectSauron encrypted LSA samples
Detection Logic
uint16(0) == 0x5A4D and (any of ($a*) or ( pe.exports("InitializeChangeNotify") and pe.exports("PasswordChangeNotify") and math.entropy(0x400, filesize) >= 7.5 )) and filesize < 1000000 Field Validations
Loading…
Comments (0)
Loading comments...