id: ddostf-malware info: name: DDoSTf Malware - Detect author: daffainfo severity: info reference: - http://blog.malwaremustdie.org/2016/01/mmd-0048-2016-ddostf-new-elf-windows.html - https://github.com/Yara-Rules/rules/blob/master/malware/MALW_DDoSTf.yar tags: malware,file file: - extensions: - all matchers-condition: and matchers: - type: word part: raw words: - 'ddos.tf' - 'Accept-Language: zh' - '%d Kb/bps|%d%%' condition: and - type: binary binary: - 'E8AEBEE7BDAE5443505F4B454550494E54564CE99499E8AFAFEFBC9A00' - 'E8AEBEE7BDAE5443505F4B454550434E54E99499E8AFAFEFBC9A00' condition: and # digest: 490a00463044022069c37b9b0b031a463f234c65dabef2ccf82eafbbf75453e3742a81fd59e4e222022050ab2c041ae193aa639c9d0bce242bee402c7c1f3edce808308c9eca74636193:922c64590222798bb761d5b6d8e72950