YARA unknown stable yara

ransomware_PetrWrap [malware]

Rule to detect PetrWrap ransomware samples

View Source

Detection Logic

uint16(0) == 0x5A4D and filesize < 1000000 and any of them

Field Validations

Loading…

Comments (0)

Loading comments...