Andromeda_MalBot_Jun_1A
Description
Detects a malicious Worm Andromeda / RETADUP
Query · yara
strings:
$x1 = "%temp%\\FolderN\\name.exe" fullword wide
$x2 = "%temp%\\FolderN\\name.exe.lnk" fullword wide
$x3 = "\\Startup\\name.exe" wide
$x4 = "firefox.exe.exe" fullword wide
$x5 = "\\Desktop\\New folder\\dark.exe" wide
$x6 = "\\x86\\Release\\word.pdb" ascii
$x7 = "\\obj\\Release\\botkill.pdb" ascii
$s1 = "4System.Web.Services.Protocols.SoapHttpClientProtocol" fullword ascii
$s2 = "svhost.exe" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 2000KB and ( 1 of ($x*) or 2 of them )