HKTL_LazyCat_LogEraser
Description
Detetcs a tool used in the Australian Parliament House network compromise
Query · yara
strings:
$x1 = "LazyCat.dll" ascii wide fullword
$x2 = ".local_privilege_escalation.rotten_potato" ascii wide
$x3 = "LazyCat.Extension" ascii wide
$x4 = " MEOWof" ascii wide
$x5 = "VirtualSite: {0}, Address: {1:X16}, Name: {2}, Handle: {3:X16}, LogPath: {4}" fullword wide
$s1 = "LazyCat" fullword ascii wide
$s2 = "$e3ff37f2-85d7-4b24-a385-7eeb1f5a9562"
$s3 = "local -> remote {0} bytes"
$s4 = "remote -> local {0} bytes"
condition:
3 of them