YARA unknown stable yara

DarkEYEv3_Cryptor [crypto]

Rule to detect DarkEYEv3 encrypted executables (often malware)

View Source

Detection Logic

uint16(0) == 0x5a4d and $s0

Field Validations

Loading…

Comments (0)

Loading comments...