GoldDragon_Ghost419_RAT
Description
Detects Ghost419 RAT from Gold Dragon report
Query · yara
strings:
$x2 = "WebKitFormBoundarywhpFxMBe19cSjFnG" ascii
$x3 = "\\Microsoft\\HNC\\" ascii
$x4 = "\\anternet abplorer" ascii
$x5 = "%s\\abxplore.exe" fullword ascii
$x6 = "GHOST419" fullword ascii
$x7 = "I,m Online. %04d - %02d - %02d - %02d - %02d" fullword ascii
$x8 = "//////////////////////////regkeyenum//////////////" ascii
$s0 = "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; .NET CLR 1.1.4322)" fullword ascii
$s1 = "www.GoldDragon.com" fullword ascii
$s2 = "/c systeminfo >> %s" fullword ascii
$s3 = "/c dir %s\\ >> %s" fullword ascii
$s4 = "DownLoading %02x, %02x, %02x" fullword ascii
$s5 = "Tran_dll.dll" fullword ascii
$s6 = "MpCmdRunkr.dll" fullword ascii
$s7 = "MpCmdRun.dll" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 600KB and (
( pe.exports("ExportFunction") and pe.number_of_exports == 1 ) or
( 1 of ($x*) and 1 of ($s*) ) or
3 of them
)