MAL_Enfal_Nov22
Description
Detects a certain type of Enfal Malware
Query · yara
strings:
$xop1 = { 00 00 83 c9 ff 33 c0 f2 ae f7 d1 49 b8 ff 8f 01 00 2b c1 }
$s1 = "POWERPNT.exe" fullword ascii
$s2 = "%APPDATA%\\Microsoft\\Windows\\" ascii
$s3 = "%HOMEPATH%" fullword ascii
$s4 = "Server2008" fullword ascii
$s5 = "%ComSpec%" fullword ascii
condition:
uint16(0) == 0x5a4d and
filesize < 200KB and
( 1 of ($x*) or 3 of ($s*) )