APT_Lazarus_Aug18_1
Description
Detects Lazarus Group Malware
Query · yara
strings:
$s1 = "mws2_32.dll" fullword wide
$s2 = "%s.bat" fullword wide
$s3 = "%s%s%s \"%s > %s 2>&1\"" fullword wide
$s4 = "Microsoft Corporation. All rights reserved." fullword wide
$s5 = "ping 127.0.0.1 -n 3" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 500KB and (
pe.imphash() == "3af996e4f960108533e69b9033503f40" or
4 of them
)