TA17_293A_malware_1
Description
inveigh pen testing tools & related artifacts
Query · yara
strings:
$n1 = "file://"
$ax1 = "184.154.150.66"
$ax2 = "5.153.58.45"
$ax3 = "62.8.193.206"
$ax4 = "/pshare1/icon"
$ax5 = "/ame_icon.png"
$ax6 = "/1/ree_stat/p"
/* Too many false positives with these strings
$au1 = "/icon.png"
$au2 = "/notepad.png"
$au3 = "/pic.png"
*/
$s1 = "(g.charCodeAt(c)^l[(l[b]+l[e])%256])"
$s2 = "for(b=0;256>b;b++)k[b]=b;for(b=0;256>b;b++)"
$s3 = "VXNESWJfSjY3grKEkEkRuZeSvkE="
$s4 = "NlZzSZk="
$s5 = "WlJTb1q5kaxqZaRnser3sw=="
$x1 = { 87D081F60C67F5086A003315D49A4000F7D6E8EB12000081F7F01BDD21F7DE }
$x2 = { 33C42BCB333DC0AD400043C1C61A33C3F7DE33F042C705B5AC400026AF2102 }
$x3 = "fromCharCode(d.charCodeAt(e)^k[(k[b]+k[h])%256])"
$x4 = "ps.exe -accepteula \\%ws% -u %user% -p %pass% -s cmd /c netstat"
$x5 = { 22546F6B656E733D312064656C696D733D5C5C222025254920494E20286C6973742E74787429 }
$x6 = { 68656C6C2E657865202D6E6F65786974202D657865637574696F6E706F6C69637920627970617373202D636F6D6D616E6420222E202E5C496E76656967682E70 }
$x7 = { 476F206275696C642049443A202266626433373937623163313465306531 }
$x8 = { 24696E76656967682E7374617475735F71756575652E4164642822507265737320616E79206B657920746F2073746F70207265616C2074696D65 }
//specific malicious word document PK archive
$x9 = { 2F73657474696E67732E786D6CB456616FDB3613FEFE02EF7F10F4798E64C54D06A14ED125F19A225E87C9FD0194485B }
$x10 = { 6C732F73657474696E67732E786D6C2E72656C7355540500010076A41275780B0001040000000004000000008D90B94E03311086EBF014D6F4D87B48214471D2 }
$x11 = { 8D90B94E03311086EBF014D6F4D87B48214471D210A41450A0E50146EBD943F8923D41C9DBE3A54A240ACA394A240ACA39 }
$x12 = { 8C90CD4EEB301085D7BD4F61CDFEDA092150A1BADD005217B040E10146F124B1F09FEC01B56F8FC3AA9558B0B4 }
$x13 = { 8C90CD4EEB301085D7BD4F61CDFEDA092150A1BADD005217B040E10146F124B1F09FEC01B56F8FC3AA9558B0B4 }
$x14 = "http://bit.ly/2m0x8IH"
condition:
( $n1 and 1 of ($ax*) ) or
2 of ($s*) or
1 of ($x*)