IceFog_Malware_Feb18_1
Description
Detects IceFog malware
Query · yara
strings:
$s1 = "cmd /c %c%s%c" fullword ascii
$s2 = "temp.bat" fullword ascii
$s3 = "c:\\windows\\debug\\wia\\help" fullword wide
$s4 = "/getorder.aspx?hostname=" fullword wide
$s5 = "\\filecfg_temp.dat" wide
$s6 = "Unknown operating system " fullword wide
$s7 = "kastygost.compress.to" fullword wide
$s8 = "/downloads/" wide
$s9 = "\\key.dat" wide
condition:
uint16(0) == 0x5a4d and filesize < 2000KB and 4 of them