Sneed-Reactivity/yara-mikesxrs/alienvault/NKRivts.yar
Sam Sneed 08e8d462fe OMG ISTG PLS WORK
RED PILL 🔴 💊
2024-07-25 12:43:35 -05:00

12 lines
363 B
Text

rule rivts_pdb {
meta:
description = "Detects Rivts based on PDB folder"
author="cdoman@alienvault.com"
tlp ="white"
license = "MIT License"
reference = "https://www.alienvault.com/blogs/security-essentials/north-korean-cyber-attacks-and-collateral-damage"
strings:
$m = "F:\\meWork\\" nocase wide ascii
condition:
uint16(0) == 0x5a4d and any of them
}