-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathAPT34_LONGWATCH.yara
43 lines (39 loc) · 1.53 KB
/
APT34_LONGWATCH.yara
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
rule APT34_LONGWATCH: apt34 winmalware keylogger
{
meta:
Description = "APT34 Keylogger"
Reference = "https://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declining-apt34-invite-to-join-their-professional-network.html"
strings:
$log = "c:\\windows\\temp\\log.txt" ascii fullword
$clipboard = "---------------CLIPBOARD------------" ascii fullword
$func0 = "\"Main Invoked.\"" ascii fullword
$func1 = "\"Main Returned.\"" ascii fullword
$logger3 = ">---------------------------------------------------" ascii fullword
$logger4 = "[ENTER]" ascii fullword
$logger5 = "[CapsLock]" ascii fullword
$logger6 = "[CRTL]" ascii fullword
$logger7 = "[PAGE_UP]" ascii fullword
$logger8 = "[PAGE_DOWN]" ascii fullword
$logger9 = "[HOME]" ascii fullword
$logger10 = "[LEFT]" ascii fullword
$logger11 = "[RIGHT]" ascii fullword
$logger12 = "[DOWN]" ascii fullword
$logger13 = "[PRINT]" ascii fullword
$logger14 = "[PRINT SCREEN]" ascii fullword
$logger15 = "[INSERT]" ascii fullword
$logger16 = "[SLEEP]" ascii fullword
$logger17 = "[PAUSE]" ascii fullword
$logger18 = "[TAB]" ascii fullword
$logger19 = "[ESC]" ascii fullword
$logger20 = "[DEL]" ascii fullword
$logger21 = "[ALT]" ascii fullword
condition:
uint16(0) == 0x5a4d
and
$log
and
all of ($func*)
and
all of ($logger*)
and $clipboard
}