Emdivi_Gen1
Description
Detects Emdivi Malware
Query · yara
strings: $x1 = "wmic nteventlog where filename=\"SecEvent\" call cleareventlog" fullword wide $x2 = "del %Temp%\\*.exe %Temp%\\*.dll %Temp%\\*.bat %Temp%\\*.ps1 %Temp%\\*.cmd /f /q" fullword wide $x3 = "userControl-v80.exe" fullword ascii $s1 = "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727.42)" fullword wide $s2 = "http://www.msftncsi.com" fullword wide $s3 = "net use | find /i \"c$\"" fullword wide $s4 = " /del /y & " fullword wide $s5 = "\\auto.cfg" wide $s6 = "/ncsi.txt" fullword wide $s7 = "Dcmd /c" fullword wide $s8 = "/PROXY" fullword wide condition: uint16(0) == 0x5a4d and filesize < 800KB and all of them