Waterbear_11_Jun17
Description
Detects malware from Operation Waterbear
Query · yara
strings:
$s1 = "/Pages/%u.asp" fullword wide
$s2 = "NVIDIA Corporation." fullword wide
$s3 = "tqxbLc|fP_{eOY{eOX{eO" fullword ascii
$s4 = "Copyright (C) 2005" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 1000KB and all of them )