SUSP_Modified_PEFile_Header_Anomaly_Aug20

Rule Info

Name
SUSP_Modified_PEFile_Header_Anomaly_Aug20
Author
Florian Roth
Description
Detects a portable executable file with malformed or corrupt header
Score
50
Reference
Internal Research
Date
2020-08-21
Modified
2023-12-14
Minimum Yara
1.7
Rule Hash
476b8c76ec5b4c323101e5cf6b6a0175
Tags
['SUSP', 'FILE', 'EXE', 'ANOMALY']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
0

Rule Matches

No matches yet

Rule Matches per Month (last 24 months)