YARA unknown stable yara

IDTools_For_WinXP_IdtTool [malware]

Chinese Hacktool Set - file IdtTool.exe

View Source

Detection Logic

uint16(0) == 0x5a4d and filesize < 25KB and all of them

Field Validations

Loading…

Comments (0)

Loading comments...