Slingshot_APT_Malware_4
Description
Detects malware from Slingshot APT
Query · yara
strings:
$x1 = "Ss -a 4104 -s 257092 -o 8 -l 406016 -r 4096 -z 315440" fullword wide
$s1 = "Slingshot" fullword ascii
$s2 = "\\\\?\\e:\\$Recycle.Bin\\" wide
$s3 = "LineRecs.reloc" fullword ascii
$s4 = "EXITGNG" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 1000KB and (
$x1 or 2 of them
)