id: shimratreporter-malware info: name: ShimRatReporter Malware - Detect author: daffainfo severity: info reference: https://github.com/Yara-Rules/rules/blob/master/malware/RAT_Shim.yar tags: malware,file file: - extensions: - all matchers: - type: word part: raw words: - "IP-INFO" - "Network-INFO" - "OS-INFO" - "Process-INFO" - "Browser-INFO" - "QueryUser-INFO" - "Users-INFO" - "Software-INFO" - "%02X-%02X-%02X-%02X-%02X-%02X" - "(from environment) = %s" - "NetUserEnum" - "GetNetworkParams" condition: and # digest: 4b0a004830460221008a0d2f7db3a9984378cf10f44fa78b4160a493e9e3b8bd7c6ae0ae600b0777cb022100b36b3c25e9b677e7c62fc45315d79df0f7157479630f3e871854cd7557538f54:922c64590222798bb761d5b6d8e72950