Waterbear_2_Jun17
Description
Detects malware from Operation Waterbear
Query · yara
strings:
$s1 = "downloading movie" fullword ascii
$s2 = "name=\"test.exe\"/>" fullword ascii
$s3 = "<description>Test Application</description>" fullword ascii
$s4 = "UI look 2003" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 1000KB and all of them )