Windows_Generic_Threat_7a49053e


Description

Windows.Generic.Threat

Query · yara

strings:
        $a1 = { 5D 76 3F 3F 32 40 59 41 50 41 58 49 40 5A 66 }
        $a2 = { 41 75 74 68 6F 72 69 7A 61 26 42 61 73 69 63 48 24 }
        $a3 = { 4A 7E 4C 65 61 76 65 47 65 74 51 75 65 }
    condition:
        all of them
Raw source Windows_Generic_Threat_7a49053e · YARA
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
rule Windows_Generic_Threat_7a49053e {
    meta:
        author = "Elastic Security"
        id = "7a49053e-5ae4-4141-9471-4a92e0ee226e"
        fingerprint = "49c41c5372da04b770d903013ee7f71193a4650340fd4245d6d5bceff674d637"
        creation_date = "2024-01-29"
        last_modified = "2024-02-08"
        threat_name = "Windows.Generic.Threat"
        reference_sample = "29fb2b18cfd72a2966640ff59e67c89f93f83fc17afad2dfcacf9f53e9ea3446"
        severity = 50
        arch_context = "x86, arm64"
        scan_context = "file, memory"
        license = "Elastic License v2"
        os = "windows"
    strings:
        $a1 = { 5D 76 3F 3F 32 40 59 41 50 41 58 49 40 5A 66 }
        $a2 = { 41 75 74 68 6F 72 69 7A 61 26 42 61 73 69 63 48 24 }
        $a3 = { 4A 7E 4C 65 61 76 65 47 65 74 51 75 65 }
    condition:
        all of them
}

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.