RevengeRAT_Sep17
Description
Detects RevengeRAT malware
Query · yara
strings:
$x1 = "Nuclear Explosion.g.resources" fullword ascii
$x4 = "5B1EE7CAD3DFF220A95D1D6B91435D9E1520AC41" fullword ascii
$x5 = "\\RevengeRAT\\" ascii
$x6 = "Revenge-RAT client has been successfully installed." ascii
$x7 = "Nuclear Explosion.exe" fullword ascii
$x8 = " Revenge-RAT 201" wide
$s1 = "{11111-22222-20001-00001}" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 500KB and 1 of ($x*) ) or ( 3 of them )