APT_Tick_HomamDownloader_Jun18
Description
Detects HomamDownloader from Tick group incident - Weaponized USB
Query · yara
strings:
$s1 = "cmd /c hostname >>" fullword ascii
$s2 = "Mstray.exe" fullword ascii
$s3 = "msupdata.exe" fullword ascii
$s5 = "Windows\\CurrentVersion\\run" fullword ascii
$s6 = "Content-Type: */*" fullword ascii
$s11 = "Mozilla/4.0 (compatible; MSIE 8.0; Win32)" fullword ascii /* Goodware String - occured 3 times */
condition:
uint16(0) == 0x5a4d and filesize < 30KB and 3 of them