mirror of
https://github.com/valitydev/signature-base.git
synced 2024-11-06 10:05:18 +00:00
Suspicious BAT helper file
This commit is contained in:
parent
4468bb80b3
commit
240f53b398
19
yara/gen_susp_bat_aux.yar
Normal file
19
yara/gen_susp_bat_aux.yar
Normal file
@ -0,0 +1,19 @@
|
||||
|
||||
rule SUSP_BAT_Aux_Jan20_1 {
|
||||
meta:
|
||||
description = "Detects BAT file often dropped to cleanup temp dirs during infection"
|
||||
author = "Florian Roth"
|
||||
reference = "https://medium.com/@quoscient/the-chicken-keeps-laying-new-eggs-uncovering-new-gc-maas-tools-used-by-top-tier-threat-actors-531d80a6b4e9"
|
||||
date = "2020-01-29"
|
||||
license = "https://creativecommons.org/licenses/by-nc/4.0/"
|
||||
score = 65
|
||||
hash1 = "f5d558ec505b635b1e37557350562ad6f79b3da5cf2cf74db6e6e648b7a47127"
|
||||
strings:
|
||||
$s1 = "if exist \"C:\\Users\\" ascii
|
||||
$s2 = "\\AppData\\Local\\Temp\\" ascii
|
||||
$s3 = "del \"C:\\Users\\" ascii
|
||||
$s4 = ".bat\"" ascii
|
||||
$s5 = ".exe\" goto" ascii
|
||||
condition:
|
||||
uint8(0) == 0x3a and filesize <= 1KB and all of them
|
||||
}
|
Loading…
Reference in New Issue
Block a user