SUSP_PE_Discord_Attachment_Oct21_1
Description
Detects suspicious executable with reference to a Discord attachment (often used for malware hosting on a legitimate FQDN)
Query · yara
strings:
$x1 = "https://cdn.discordapp.com/attachments/" ascii wide
condition:
uint16(0) == 0x5a4d
and filesize < 5000KB
and 1 of them