Common Information
Type | Value |
---|---|
Value |
rule Windows_Trojan_GHOSTPULSE_2 { meta: author = "Elastic Security" creation_date = "2024-10-10" last_modified = "2024-10-10" os = "Windows" arch = "x86" category_type = "Trojan" family = "GHOSTPULSE" threat_name = "Windows.Trojan.GHOSTPULSE" license = "Elastic License v2" strings: $a1 = { 48 83 EC 18 C7 04 24 00 00 00 00 8B 04 24 48 8B 4C 24 20 0F B7 04 41 85 C0 74 0A 8B 04 24 FF C0 89 04 24 EB E6 C7 44 24 08 00 00 00 00 8B 04 24 FF C8 8B C0 48 8B 4C 24 20 0F B7 04 41 83 F8 5C } condition: all of them } |
Category | |
Type | Yara Rule |
Misp Type | |
Description |