MAL_BurningUmbrella_Sample_22
Description
Detects malware sample from Burning Umbrella report
Query · yara
strings:
$s1 = "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\" ascii
$s3 = "Content-Disposition: form-data; name=\"txt\"; filename=\"" fullword ascii
$s4 = "Fail To Enum Service" fullword ascii
$s5 = "Host Power ON Time" fullword ascii
$s6 = "%d Hours %2d Minutes %2d Seconds " fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 200KB and 4 of them