APT_CryWiper_Dec22
Description
Detects CryWiper malware samples
Query · yara
strings:
$x1 = "Software\\Sysinternals\\BrowserUpdate"
$sx1 = "taskkill.exe /f /im MSExchange*"
$s1 = "SYSTEM\\CurrentControlSet\\Control\\Terminal Server" ascii
$s2 = "fDenyTSConnections" ascii
condition:
1 of ($x*) or all of ($s*)