id: bandook-malware info: name: Bandook Malware - Detect author: daffainfo severity: info reference: https://github.com/Yara-Rules/rules/blob/master/malware/RAT_Ratdecoders.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - "aaaaaa1|" - "aaaaaa2|" - "aaaaaa3|" - "aaaaaa4|" - "aaaaaa5|" - "%s%d.exe" - "astalavista" - "givemecache" - "%s\\system32\\drivers\\blogs\\*" - "bndk13me" condition: and # digest: 490a00463044022007979ba459fa852d0b1fd07c059ee0adb0247b99212b122b9f3b6e1e4048588d02205a59508d1df975e27c8120cd265e4c11e535631c16b5be4ca71b9595c4326cc2:922c64590222798bb761d5b6d8e72950