IronPanda_Malware1
Description
Iron Panda Malware
Query · yara
strings: $x1 = "activedsimp.dll" fullword wide $s1 = "get_BadLoginAddress" fullword ascii $s2 = "get_LastFailedLogin" fullword ascii $s3 = "ADS_UF_ENCRYPTED_TEXT_PASSWORD_ALLOWED" fullword ascii $s4 = "get_PasswordExpirationDate" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 300KB and all of them