APT_Thrip_Sample_Jun18_2
Description
Detects sample found in Thrip report by Symantec
Query · yara
strings:
$s1 = "C:\\WINDOWS\\system32\\sysprep\\cryptbase.dll" fullword ascii
$s2 = "ProbeScriptFint" fullword wide
$s3 = "C:\\WINDOWS\\system32\\cmd.exe" fullword ascii /* Goodware String - occured 2 times */
condition:
uint16(0) == 0x5a4d and filesize < 60KB and all of them