YARA unknown stable yara

IDTools_For_WinXP_IdtTool_2 [malware]

Chinese Hacktool Set - file IdtTool.sys

View Source

Detection Logic

uint16(0) == 0x5a4d and filesize < 7KB and all of them

Field Validations

Loading…

Comments (0)

Loading comments...