id: codoso-pgv-malware-hash info: name: Codoso APT PGV_PVID Malware Hash - Detect author: pussycat0x severity: info description: | Detects Codoso APT PGV_PVID Malware. reference: - https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks - https://github.com/Yara-Rules/rules/blob/master/malware/APT_Codoso.yar tags: malware,apt,codoso file: - extensions: - all matchers: - type: dsl dsl: - "sha256(raw) == '4b16f6e8414d4192d0286b273b254fa1bd633f5d3d07ceebd03dfdfc32d0f17f'" - "sha256(raw) == '13bce64b3b5bdfd24dc6f786b5bee08082ea736be6536ef54f9c908fd1d00f75'" - "sha256(raw) == 'bc0b885cddf80755c67072c8b5961f7f0adcaeb67a1a5c6b3475614fd51696fe'" - "sha256(raw) == '4b16f6e8414d4192d0286b273b254fa1bd633f5d3d07ceebd03dfdfc32d0f17f'" condition: or # digest: 4a0a00473045022100880ccf3fafac7e58b750b727c22e2d7284b5c2de263a5f5157a2abce9d951e2b02205f7f4fda15882dc695ba9258038ab6b6a2d72a07b2fe7e2f6dc7a5e9dbab223d:922c64590222798bb761d5b6d8e72950