Waterbear_13_Jun17
Description
Detects malware from Operation Waterbear
Query · yara
strings:
$s1 = "%WINDIR%\\PCHealth\\HelpCtr\\Binaries\\pchsvc.dll" fullword ascii
$s2 = "brnew.exe" fullword ascii
$s3 = "ChangeServiceConfig failed (%d)" fullword ascii
$s4 = "Proxy %d:%s %d" fullword ascii
$s5 = "win9807.tmp" fullword ascii
$s7 = "Service stopped successfully" fullword ascii
$s8 = "current dns:%s" fullword ascii
$s9 = "%c%u|%u|%u|%u|%u|" fullword ascii
$s10 = "[-]send %d: " fullword ascii
condition:
( uint16(0) == 0x5a4d and filesize < 300KB and 4 of them )