APT_Lazarus_Dropper_Jun18_1
Description
Detects Lazarus Group Dropper
Query · yara
strings:
$s1 = /%s\\windows10-kb[0-9]{7}.exe/ fullword ascii
$s2 = "EYEJIW" fullword ascii
$s3 = "update" fullword wide /* Goodware String - occured 254 times */
condition:
uint16(0) == 0x5a4d and filesize < 21000KB and (
pe.imphash() == "fcac768eff9896d667a7c706d70712ce" or
all of them
)