Suckfly_Nidiran_Gen_3
Description
Detects Suckfly Nidiran Trojan
Query · yara
strings:
$x1 = "RUN SHELLCODE FAIL" fullword ascii
$x2 = "RUN PROCESS FAILD!" fullword ascii
$x3 = "DOWNLOAD FILE FAILD" fullword ascii
$x4 = "MODIFYCONFIG FAIL!" fullword ascii
$x5 = "GetFileAttributes FILE FAILD" fullword ascii
$x6 = "MODIFYCONFIG SUCC!" fullword ascii
$s1 = "cmd.exe /c %s" fullword ascii
$s2 = "error to create pipe!" fullword ascii
$s3 = "%s\\%08x.exe" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 300KB and (
pe.imphash() == "ae0f4ebf7e8ce91d6548318a3cf82b7a" or
1 of ($x*) or
2 of them
)