APT_Cloaked_PsExec
Description
Looks like a cloaked PsExec. This may be APT group activity.
Query · yara
strings: $s0 = "psexesvc.exe" wide fullword $s1 = "Sysinternals PsExec" wide fullword condition: uint16(0) == 0x5a4d and $s0 and $s1 and not filename matches /(psexec.exe|PSEXESVC.EXE|PsExec64.exe)$/is and not filepath matches /RECYCLE.BIN\\S-1/