WinAgent_BadPatch_2
Description
Detects samples mentioned in BadPatch report
Query · yara
strings:
$s1 = "myAction=shell_result&serialNumber=" fullword wide
$s2 = "\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Login Data.*" wide
$s3 = "\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles" wide
$s4 = "\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Cookies.*" wide
$s5 = "newSHELL[" fullword wide
$s6 = "\\file1.txt" wide
$s7 = "myAction=newGIF&serialNumber=" fullword wide
$s8 = "\\Storege1" wide
$s9 = "\\Microsoft\\mac.txt" wide
$s10 = "spytube____:" fullword ascii
$s11 = "0D0700045F5C5B0312045A04041F40014B1D11004A1F19074A141100011200154B031C04" fullword wide
$s12 = "16161A1000012B162503151851065A1A0007" fullword wide
$s13 = "-- SysFile...." fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 700KB and 3 of them )