VBS_Obfuscated_Mal_Feb18_1
Description
Detects malicious obfuscated VBS observed in February 2018
Query · yara
strings:
$x1 = "A( Array( (1* 2^1 )+" ascii
$x2 = ".addcode(A( Array(" ascii
$x3 = "false:AA.send:Execute(AA.responsetext):end" ascii
$x4 = "& A( Array( (1* 2^1 )+" ascii
$s1 = ".SYSTEMTYPE:NEXT:IF (UCASE(" ascii
$s2 = "A = STR:next:end function" ascii
$s3 = "&WSCRIPT.SCRIPTFULLNAME&CHR" fullword ascii
condition:
filesize < 600KB and ( 1 of ($x*) or 3 of them )