IronPanda_Malware3
Description
Iron Panda Malware
Query · yara
strings: $s0 = "PluginDeflater.exe" fullword wide $s1 = ".Deflated" fullword wide $s2 = "PluginDeflater" fullword ascii $s3 = "DeflateStream" fullword ascii /* Goodware String - occured 1 times */ $s4 = "CompressionMode" fullword ascii /* Goodware String - occured 4 times */ $s5 = "System.IO.Compression" fullword ascii /* Goodware String - occured 6 times */ condition: uint16(0) == 0x5a4d and filesize < 10KB and all of them