Common Information
Type Value
Value
rule shadowhammer_patch {
	strings:
		$str_msi = "\\419.msi" ascii wide nocase
		$str_upd = "ASUS Live Updata" ascii wide nocase
		$str_ins = "Asusaller Application" ascii wide nocase
	condition:
		2 of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2019-03-29 24 A Hammer Lurking In The Shadows - F-Secure Blog