Slingshot_APT_Malware_3
Description
Detects malware from Slingshot APT
Query · yara
strings:
$a1 = "chmhlpr.dll" fullword ascii
$s2 = "%hc%hc%hc%hc" fullword ascii
$s3 = "%hc%hc%hc=" fullword ascii
$s4 = "%hc%hc==" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 100KB and (
pe.imphash() == "2f3b3df466e24e0792e0e90d668856bc" or
pe.exports("dll_u") or
( $a1 and 2 of ($s*) )
)