DragonFly_APT_Sep17_4
Description
Detects malware from DrqgonFly APT report
Query · yara
strings:
$s1 = "screen.exe" fullword wide
$s2 = "PlatformInvokeUSER32" fullword ascii
$s3 = "GetDesktopImageF" fullword ascii
$s4 = "PlatformInvokeGDI32" fullword ascii
$s5 = "GetDesktopImage" fullword ascii
$s6 = "Too many arguments, going to store in current dir" fullword wide
condition:
( uint16(0) == 0x5a4d and filesize < 60KB and all of them )