OpCloudHopper_Malware_8
Description
Detects malware from Operation Cloud Hopper
Query · yara
strings:
$s1 = "WSHELL32.dll" fullword wide
$s2 = "operator \"\" " fullword ascii
$s3 = "\" /t REG_SZ /d \"" fullword wide
$s4 = " /f /v \"" fullword wide
$s5 = "zok]\\\\\\ZZYYY666564444" fullword ascii
$s6 = "AFX_DIALOG_LAYOUT" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 900KB and 4 of them )