id: cythosia-malware info: name: Cythosia Malware - Detect author: daffainfo severity: info reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Cythosia.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - 'HarvesterSocksBot.Properties.Resources' # digest: 490a00463044022078ad40bfbd1ef70b1a2d5f012e6f7e22f0c147b4622d3fb20bd95dca173ba3cd02207c1fd648ffed2e553b8f2d4fab5e3610c84cd330b9ec5bfcfdd6798fffcfbc68:922c64590222798bb761d5b6d8e72950