Common Information
Type | Value |
---|---|
Value |
rule apt_41_phantom_implant { meta: author = "Felipe Duarte, Security Joes" description = "Detects APT 41 Phantom Implant" sha256_reference = "3df75113ff7a9c2158ff991e1f4e1c2dcc5bd19f41caa07f1dc0aabc4f872bed" strings: $str1 = { 8B C8 69 DB ?? ?? ?? ?? 8A C3 C1 EB 08 41 30 03 49 FF C3 48 FF C9 } condition: $str1 } |
Category | |
Type | Yara Rule |
Misp Type | |
Description |