Fireball_gubed
Description
Detects Fireball malware - file gubed.exe
Query · yara
strings:
$x1 = "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\MRT.exe" fullword wide
$x2 = "tIphlpapi.dll" fullword wide
$x3 = "http://%s/provide?clients=%s&reqs=visit.startload" fullword wide
$x4 = "\\Gubed\\Release\\Gubed.pdb" ascii
$x5 = "d2hrpnfyb3wv3k.cloudfront.net" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 300KB and 1 of them )