Reaver3_Malware_Nov17_2
Description
Detects Reaver malware mentioned in PaloAltoNetworks report
Query · yara
strings:
$x1 = "WindowsUpdateReaver" fullword wide
$s1 = "\\WUpdate.~tmp" ascii
$s2 = "\\~WUpdate.lnk" ascii
$s3 = "\\services\\" ascii
$s4 = "moomjufps" fullword ascii
$s5 = "gekmomkege" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 100KB and (
pe.imphash() == "837cc5062a0758335b257ea3b27972b2" or
1 of ($x*) or
3 of them
)