Waterbear_7_Jun17
Description
Detects malware from Operation Waterbear
Query · yara
strings:
$s1 = "Bluthmon.exe" fullword wide
$s2 = "Motomon.exe" fullword wide
$s3 = "%d.%s%d%d%d" fullword ascii
$s4 = "mywishes.hlp" fullword ascii
$s5 = "filemon.rtf" fullword ascii
condition:
( uint16(0) == 0x5a4d and filesize < 80KB and all of them )