Slingshot_APT_Malware_1
Description
Detects malware from Slingshot APT
Query · yara
strings:
$s1 = "SlingDll.dll" fullword ascii
$s2 = "BogusDll." ascii
$s3 = "smsvcrt -h 0x%p" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 700KB and (
pe.imphash() == "7ead4bb0d752003ce7c062adb7ffc51a" or
pe.exports("WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW0000") or
1 of them
)