APT_SH_Sandworm_Shell_Script_May20_1
Description
Detects shell script used by Sandworm in attack against Exim mail server
Query · yara
strings:
$x1 = "echo \"GRANT ALL PRIVILEGES ON * . * TO 'mysqldb'@'localhost';\" >> init-file.txt" ascii fullword
$x2 = "import base64,sys;exec(base64.b64decode({2:str,3:lambda b:bytes(b,'UTF-8')}[sys.version" ascii fullword
$x3 = "sed -i -e '/PasswordAuthentication/s/no/yes/g; /PermitRootLogin/s/no/yes/g;" ascii fullword
$x4 = "useradd -M -l -g root -G root -b /root -u 0 -o mysql_db" ascii fullword
$s1 = "/ip.php?port=${PORT}\"" ascii fullword
$s2 = "sed -i -e '/PasswordAuthentication" ascii fullword
$s3 = "PATH_KEY=/root/.ssh/authorized_keys" ascii fullword
$s4 = "CREATE USER" ascii fullword
$s5 = "crontab -l | { cat; echo" ascii fullword
$s6 = "mysqld --user=mysql --init-file=/etc/opt/init-file.txt --console" ascii fullword
$s7 = "sshkey.php" ascii fullword
condition:
uint16(0) == 0x2123 and
filesize < 20KB and
1 of ($x*) or 4 of them