SUSP_Renamed_Bitdefender_Submission_Wizard_Feb26
Description
Detects renamed Bitdefender Submission Wizard, seen being used in the compromise of the infrastructure hosting Notepad++ by Chinese APT group Lotus Blossom
Query · yara
strings:
$s1 = "BDSubWiz.exe" wide fullword
$s2 = "Bitdefender Submission Wizard" wide
$s3 = "Software\\Bitdefender" wide
condition:
uint16(0) == 0x5a4d
and all of ($s*)
and not filename == "BDSubWiz.exe"