id: dexter-malware info: name: Dexter Malware - Detect author: daffainfo severity: info reference: - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Dexter.yar - http://goo.gl/oBvy8b tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - 'Java Security Plugin' - '%s\\%s\\%s.exe' - 'Sun Java Security Plugin' - '\\Internet Explorer\\iexplore.exe' condition: and # digest: 4b0a00483046022100a9287ff95aaf311e7c3268c65e993cb4467bfbb081b6232136aa8d2dc9deea78022100b630b834786bcd6d95a436f09629e6cb330112f7306659b2a36cba93f3203811:922c64590222798bb761d5b6d8e72950