APT_Script_AUS_4
Description
Detetcs a script involved in the Australian Parliament House network compromise
Query · yara
strings:
$x1 = "myMutex = CreateMutex(0, 1, \"teX23stNew\")" fullword ascii
$x2 = "mmpath = Environ(appdataPath) & \"\\\" & \"Microsoft\" & \"\\\" & \"mm.accdb\"" fullword ascii
$x3 = "Dim mmpath As String, newmmpath As String, appdataPath As String" fullword ascii
$x4 = "'MsgBox \"myMutex Created\" Do noting" fullword ascii
$x5 = "appdataPath = \"app\" & \"DatA\"" fullword ascii
$x6 = ".DoCmd.Close , , acSaveYes" fullword ascii
condition:
filesize < 7KB and 1 of them