Closed Icaro-Cesar closed 5 months ago
Inserting new unpacked IcedID memory detection signature. The rule has been tested, and has a low false positive rate.
I also tested the rule on the unpac.me platform, and it returned matches only with samples from the IcedID family.
Inserting new unpacked IcedID memory detection signature. The rule has been tested, and has a low false positive rate.
I also tested the rule on the unpac.me platform, and it returned matches only with samples from the IcedID family.