YARA unknown stable yara

apt_win32_dll_rat_hiZor_RAT [malware]

Detects hiZor RAT

View Source

Detection Logic

(uint16(0) == 0x5A4D or uint32(0) == 0x4464c457f) and (all of them)

Field Validations

Loading…

Comments (0)

Loading comments...