MAL_AirdViper_Sample_Apr18_1
Description
Detects Arid Viper malware sample
Query · yara
strings:
$x1 = "cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del \"%s\"" fullword ascii
$x2 = "daenerys=%s&" ascii
$x3 = "betriebssystem=%s&anwendung=%s&AV=%s" ascii
$s1 = "Taskkill /IM %s /F & %s" fullword ascii
$s2 = "/api/primewire/%s/requests/macKenzie/delete" fullword ascii
$s3 = "\\TaskWindows.exe" ascii
$s4 = "MicrosoftOneDrives.exe" fullword ascii
$s5 = "\\SeanSansom.txt" ascii
condition:
uint16(0) == 0x5a4d and filesize < 6000KB and (
1 of ($x*) or
4 of them
)