SunOrcal_Malware_Nov17_1
Description
Detects Reaver malware mentioned in PaloAltoNetworks report
Query · yara
strings:
$x1 = "kQZ6l5t1kAlsjmBzsCZPrSpQn5tFrChLtTdsgTlOsClKt5pBsDdFrSVshnxMr6ZOpn9slndBsy1jq6lIr216rSNApn9P" fullword ascii
/* $x2 = "!!!system" fullword ascii - more specific: */
$x2 = { 00 00 00 00 00 00 00 00 00 00 00 00 21 21 21 73
79 73 74 65 6D 00 00 00 00 00 00 00 00 00 00 00 }
$x3 = "!!!url!!!" fullword ascii
$x4 = "h4NcbkdLrCpFpPQ=" fullword ascii
$x5 = "GloablCryptNv1" fullword ascii
$x6 = "Gloabl\\CryptNv1" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 200KB and 1 of them