Slingshot_APT_Malware_2
Description
Detects malware from Slingshot APT
Query · yara
strings:
$x1 = "\\\\?\\c:\\RECYCLER\\S-1-5-21-2225084468-623340172-1005306204-500\\INFO5" fullword wide
$x_slingshot = {09 46 BE 57 42 DD 70 35 5E }
$s1 = "Opening service %s for stop access failed.#" fullword wide
$s2 = "LanMan setting <%s> is ignored because system has a higher value already." fullword wide
$s3 = "\\DosDevices\\amxpci" wide
$s4 = "lNTLMqSpPD" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 900KB and ( 1 of ($x*) or 4 of them )