id: glasses-malware info: name: Glasses Malware - Detect author: daffainfo severity: info reference: - https://citizenlab.ca/2013/02/apt1s-glasses-watching-a-human-rights-organization/ - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Glasses.yar tags: malware,file file: - extensions: - all matchers-condition: and matchers: - type: word part: raw words: - 'thequickbrownfxjmpsvalzydg' - 'Mozilla/4.0 (compatible; Windows NT 5.1; MSIE 7.0; Trident/4.0; %s.%s)' - '" target="NewRef">' condition: and - type: binary binary: - "B8ABAAAAAAF7E1D1EA8D04522BC8" - "B856555555F7E98B4C241C8BC2C1E81F03D0493BCA" condition: or