APT_Lazarus_Aug18_Downloader_1
Description
Detects Lazarus Group Malware Downloadery
Query · yara
strings:
$x1 = "H:\\DEV\\TManager\\" ascii
$x2 = "\\Release\\dloader.pdb" ascii
$x3 = "Z:\\jeus\\"
$x4 = "\\Debug\\dloader.pdb" ascii
$x5 = "Moz&Wie;#t/6T!2yW29ab@ad%Df324V$Yd" fullword ascii
$s1 = "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" fullword ascii
$s2 = "Error protecting memory page" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 500KB and (
( 1 of ($x*) or 2 of them )
)