APT_Cloaked_ScanLine
Description
Looks like a cloaked ScanLine Port Scanner. This may be APT group activity.
Query · yara
strings: $s0 = "ScanLine" wide fullword $s1 = "Command line port scanner" wide fullword $s2 = "sl.exe" wide fullword condition: uint16(0) == 0x5a4d and $s0 and $s1 and $s2 and not filename == "sl.exe"