id: madness-malware info: name: Madness DDOS Malware - Detect author: daffainfo severity: info reference: - https://github.com/arbor/yara/blob/master/madness.yara - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Madness.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - "TW96aWxsYS81LjAgKFdpbmRvd3M7IFU7IFdpbmRvd3MgTlQgNS4xOyBlbi1VUzsgcnY6MS44LjAuNSkgR2Vja28vMjAwNjA3MzEgRmlyZWZveC8xLjUuMC41IEZsb2NrLzAuNy40LjE" - "TW96aWxsYS81LjAgKFgxMTsgVTsgTGludXggMi40LjItMiBpNTg2OyBlbi1VUzsgbTE4KSBHZWNrby8yMDAxMDEzMSBOZXRzY2FwZTYvNi4wMQ==" - "document.cookie=" - "[\"cookie\",\"" - "\"realauth=" - "\"location\"];" - "d3Rm" - "ZXhl" condition: and # digest: 4a0a00473045022051f792d8fdfa305d5ab2037587778ab229d5024acc9068cb70f9980f11828e97022100c9fce5325c0373eff3477acb6ccdd1ef1e360f5382eb2bbb281a28a498d49aa3:922c64590222798bb761d5b6d8e72950