id: derkziel-malware info: name: Derkziel Malware - Detect author: daffainfo severity: info reference: - https://bhf.su/threads/137898/ - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Derkziel.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - '{!}DRZ{!}' - 'User-Agent: Uploador' - 'SteamAppData.vdf' - 'loginusers.vdf' - 'config.vdf' condition: and # digest: 4a0a0047304502200d170fa9be481ceece013efa9f03701a25bf9a54312e54f49af20ff8e0005e7d02210083a9bad344313d9eca866ea080d3d24f1fce9d2dc5d75e94b83f2a3d25b8931e:922c64590222798bb761d5b6d8e72950