Waterbear_5_Jun17
Description
Detects malware from Operation Waterbear
Query · yara
strings:
$a1 = "ICESWORD" fullword ascii
$a2 = "klog.dat" fullword ascii
$s1 = "\\cswbse.dll" ascii
$s2 = "WIRESHARK" fullword ascii
$s3 = "default_zz|" fullword ascii
$s4 = "%c4%u-%.2u-%.2u %.2u:%.2u" fullword ascii
$s5 = "1111%c%s" fullword ascii
condition:
( uint16(0) == 0x3d53 and filesize < 100KB and ( all of ($a*) or 3 of them ) )