NK_Miner_Malware_Jan18_1
Description
Detects Noth Korean Monero Miner mentioned in AlienVault report
Query · yara
strings:
$x0 = "c:\\users\\jawhar\\documents\\" ascii
$x1 = "C:\\Users\\Jawhar\\documents\\" ascii
$x2 = "The number of processors on this computer is {0}." fullword wide
$x3 = { 00 00 1F 43 00 3A 00 5C 00 4E 00 65 00 77 00 44
00 69 00 72 00 65 00 63 00 74 00 6F 00 72 00 79
00 00 }
$x4 = "Le fichier Hello txt n'existe pas" fullword wide
$x5 = "C:\\NewDirectory2\\info2" fullword wide
/* Incorported from Chris Doman's rule - https://goo.gl/PChE1z*/
$a = "82e999fb-a6e0-4094-aa1f-1a306069d1a5" ascii
$b = "4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRy5YeFCqgoUMnzumvS" ascii
$c = "barjuok.ryongnamsan.edu.kp" wide ascii
$d = "C:\\SoftwaresInstall\\soft" wide ascii
$e = "C:\\Windows\\Sys64\\intelservice.exe" wide ascii
$f = "C:\\Windows\\Sys64\\updater.exe" wide ascii
condition:
uint16(0) == 0x5a4d and filesize < 30KB and 1 of them