SeDLL_Javascript_Decryptor
Description
Detects SeDll - DLL is used for decrypting and executing another JavaScript backdoor such as Orz
Query · yara
strings:
$x1 = "SEDll_Win32.dll" fullword ascii
$x2 = "regsvr32 /s \"%s\" DR __CIM__" wide
$s1 = "WScriptW" fullword ascii
$s2 = "IWScript" fullword ascii
$s3 = "%s\\%s~%d" fullword wide
$s4 = "PutBlockToFileWW" fullword ascii
$s5 = "CheckUpAndDownWW" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 40KB and ( 1 of ($x*) or 4 of them )