id: blackworm-malware info: name: Blackworm Malware - Detect author: daffainfo severity: info reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_BlackWorm.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - 'm_ComputerObjectProvider' - 'MyWebServices' - 'get_ExecutablePath' - 'get_WebServices' - 'My.WebServices' - 'My.User' - 'm_UserObjectProvider' - 'DelegateCallback' - 'TargetMethod' - '000004b0' - 'Microsoft Corporation' condition: and # digest: 4a0a004730450220321a9ba25d7190220dfe7a801636bec8dd82300a4da2c00042576a880fd29287022100db2c2eaa880379c8391de61e30836de4b1ac496040c28f59da587259b3c7f089:922c64590222798bb761d5b6d8e72950