This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
( (uint16(0) == 0x5a4d) and ( (any of ($a*)) or (all of ($b*)) or (all of ($c*)) ) and filesize < 100000 )
or
( (uint32(0) == 0xe011cfd0) and ( (any of ($a*)) or (all of ($b*)) or (all of ($c*)) or (any of ($d*)) ) and filesize < 20000000 )
( (uint16(0) == 0x5a4d) and ( (any of ($a*)) or (all of ($b*)) or (all of ($c*)) ) and filesize < 100000 ) or ( (uint32(0) == 0xe011cfd0) and ( (any of ($a*)) or (all of ($b*)) or (all of ($c*)) or (any of ($d*)) ) and filesize < 20000000 )
}
rule apt_duqu2_drivers
{
rule apt_duqu2_drivers {
meta:
copyright = "Kaspersky Lab"
description = "Rule to detect Duqu 2.0 drivers"
last_modified = "2015-06-09"
version = "1.0"
meta:
copyright = "Kaspersky Lab"
description = "Rule to detect Duqu 2.0 drivers"
last_modified = "2015-06-09"
version = "1.0"
strings:
$a1="\\DosDevices\\port_optimizer" wide nocase
$a2="romanian.antihacker"
$a3="PortOptimizerTermSrv" wide
$a4="ugly.gorilla1"
$b1="NdisIMCopySendCompletePerPacketInfo"
$b2="NdisReEnumerateProtocolBindings"
$b3="NdisOpenProtocolConfiguration"
strings:
$a1="\\DosDevices\\port_optimizer" wide nocase
$a2="romanian.antihacker"
$a3="PortOptimizerTermSrv" wide
$a4="ugly.gorilla1"
$b1="NdisIMCopySendCompletePerPacketInfo"
$b2="NdisReEnumerateProtocolBindings"
$b3="NdisOpenProtocolConfiguration"
condition:
uint16(0) == 0x5A4D and (any of ($a*) ) and (2 of ($b*)) and filesize < 100000
uint16(0) == 0x5A4D and (any of ($a*) ) and (2 of ($b*)) and filesize < 100000