YARA unknown stable yara
DarkEYEv3_Cryptor [crypto]
Rule to detect DarkEYEv3 encrypted executables (often malware)
Detection Logic
uint16(0) == 0x5a4d and $s0 Field Validations
Loading…
Comments (0)
Loading comments...
Rule to detect DarkEYEv3 encrypted executables (often malware)
uint16(0) == 0x5a4d and $s0 Loading…
Loading comments...