YARA unknown stable yara

Industroyer_Malware_2 [malware]

Detects Industroyer related malware

View Source

Detection Logic

( uint16(0) == 0x5a4d and filesize < 300KB and 1 of ($x*) or 3 of them or 1 of ($a*) ) or ( 5 of them )

Field Validations

Loading…

Comments (0)

Loading comments...