YARA unknown stable yara

PoseidonGroup_Malware [malware]

Detects Poseidon Group Malware

View Source

Detection Logic

( uint16(0) == 0x5a4d and filesize < 650KB and 6 of ($s*) ) or ( 4 of ($s*) and 1 of ($a*) )

Field Validations

Loading…

Comments (0)

Loading comments...