DragonFly_APT_Sep17_3
Description
Detects malware from DrqgonFly APT report
Query · yara
strings:
$s1 = "kernel64.dll" fullword ascii
$s2 = "ws2_32.dQH" fullword ascii
$s3 = "HGFEDCBADCBA" fullword ascii
$s4 = "AWAVAUATWVSU" fullword ascii
condition:
( uint16(0) == 0x5a4d and
filesize < 40KB and (
pe.imphash() == "6f03fb864ff388bac8680ac5303584be" or
all of them
)
)