ME_Campaign_Malware_5
Description
Detects malware from Middle Eastern campaign reported by Talos
Query · yara
strings:
$s1 = "D:\\me\\do\\do\\obj\\" ascii
$s2 = "Select * from Win32_ComputerSystem" fullword wide
$s3 = "Get_Antivirus" fullword ascii
$s4 = "{{\"id\":\"{0}\",\"user\":\"{1}\",\"path\":\"{2}\"}}" fullword wide
$s5 = "update software online" fullword wide
$s6 = "time.nist.gov" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 60KB and 5 of them or all of them