id: derkziel-malware info: name: Derkziel Malware - Detect author: daffainfo severity: info reference: - https://bhf.su/threads/137898/ - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Derkziel.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - '{!}DRZ{!}' - 'User-Agent: Uploador' - 'SteamAppData.vdf' - 'loginusers.vdf' - 'config.vdf' condition: and