APT_Thrip_Sample_Jun18_4
Description
Detects sample found in Thrip report by Symantec
Query · yara
strings:
$s1 = "\\system32\\wbem\\tmf\\caches_version.db" ascii
$s2 = "ProcessName No Access" fullword ascii
$s3 = "Hwnd of Process NULL" fullword ascii
$s4 = "*********The new session is be opening:(%d)**********" fullword ascii
$s5 = "[EXECUTE]" fullword ascii
$s6 = "/------------------------------------------------------------------------" fullword ascii
$s7 = "constructor or from DllMain." fullword ascii
$s8 = "Time:%d-%d-%d %d:%d:%d" fullword ascii
$s9 = "\\info.config" ascii
condition:
uint16(0) == 0x5a4d and filesize < 400KB and 5 of them