Rule Info
Name
MAL_MSIL_NET_DuckTail_Stealer_Loader
Author
dr4k0nia
Description
Detects DuckTail stealer .NET loader
Score
80
Date
2023-06-16
Minimum Yara
1.7
Rule Hash
4bfa8d3bae06b77da8133be739f126c6
Tags
['FILE', 'MAL', 'EXE']
Required Modules
[]
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
21
Suspicious (< 10 engines)
10
Clean (0 engines)
2
Rule Matches
Timestamp
Positives
Total
Hash
VT