MAL_Xbash_JS_Sep18
Description
Detects XBash malware
Query · yara
strings:
$s1 = "var path=WSHShell" fullword ascii
$s2 = "var myObject= new ActiveXObject(" ascii
$s3 = "window.resizeTo(0,0)" fullword ascii
$s4 = "<script language=\"JScript\">" fullword ascii /* Goodware String - occured 4 times */
condition:
filesize < 5KB and 3 of them