Webshell_FOPO_Obfuscation_APT_ON_Nov17_1
Description
Detects malware from NK APT incident DE
Query · yara
strings:
$x1 = "Obfuscation provided by FOPO" fullword ascii
$s1 = "\";@eval($" ascii
$f1 = { 22 29 29 3B 0D 0A 3F 3E }
condition:
uint16(0) == 0x3f3c and filesize < 800KB and (
$x1 or
( $s1 in (0..350) and $f1 at (filesize-23) )
)