Common Information
Type Value
Value
rule NOTROBIN {
	meta:
		author = "william.ballenthin@fireeye.com"
		date_created = "2020-01-15"
	strings:
		$func_name_1 = "main.remove_bds"
		$func_name_2 = "main.xrun"
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2020-01-15 20 Vigilante Deploying Mitigation for Citrix NetScaler Vulnerability While Maintaining Backdoor | Mandiant