DefenderYara/Backdoor/Win32/Kilfuqi/Backdoor_Win32_Kilfuqi_A.yar

12 lines
542 B
Plaintext

rule Backdoor_Win32_Kilfuqi_A{
meta:
description = "Backdoor:Win32/Kilfuqi.A,SIGNATURE_TYPE_PEHSTR_EXT,02 00 02 00 02 00 00 "
strings :
$a_03_0 = {fe ff ff 4b 90 01 06 69 90 01 06 6c 90 01 06 6c 90 01 06 71 90 01 06 69 90 01 06 70 90 01 06 69 90 01 06 6c 90 01 06 61 90 01 06 6e 90 01 06 67 90 00 } //1
$a_03_1 = {0c ff ff ff 44 90 01 06 6c 90 01 06 6c 90 01 06 46 90 01 06 75 90 01 06 55 90 01 06 70 90 01 06 67 90 01 06 72 90 01 06 61 90 01 06 64 90 01 06 72 90 00 } //1
condition:
((#a_03_0 & 1)*1+(#a_03_1 & 1)*1) >=2
}