Freeenki_Infostealer_Nov17_Export_Sig_Testing
Description
Detects Freenki infostealer malware
Query · yara
condition:
uint16(0) == 0x5a4d and filesize < 3000KB and
pe.exports("getUpdate") and pe.number_of_exports == 1
Detects Freenki infostealer malware
condition:
uint16(0) == 0x5a4d and filesize < 3000KB and
pe.exports("getUpdate") and pe.number_of_exports == 1
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.