MAL_PHISH_Final_Payload_Feb25
Description
Detects possible final payload of phishing-delivered malware, where embedded shellcode is used to decrypt and execute the payload after user-supplied password input.
Query · yara
strings:
$s1 = "%lu: %s %s" wide
$s2 = "(Direct Inbound)" wide
$s3 = "(Primary Domain)" wide
$s4 = "(Forest Tree Root" wide
$s5 = "(Native Mode)" wide
$s6 = "(In Forest)" wide
$s7 = "(None)" wide
condition:
all of them