APT_APT41_HIGHNOON_BIN
Description
Detects APT41 malware HIGHNOON.BIN
Query · yara
strings:
$s1 = "PlusDll.dll" fullword ascii
$s2 = "\\Device\\PORTLESS_DeviceName" wide
$s3 = "%s%s\\Security" fullword ascii
$s4 = "%s\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings" fullword ascii
$s5 = "%s%s\\Enum" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 600KB and (
pe.imphash() == "b70358b00dd0138566ac940d0da26a03" or
3 of them
)