"value":"rule apt_c16_win_swisyn {\r\nmeta:\r\n author = \"@dragonthreatlab\"\r\n md5 = \"a6a18c846e5179259eba9de238f67e41\"\r\n description = \"File matching the md5 above tends to only live in memory, hence the lack of MZ header check.\"\r\nstrings:\r\n $mz = {4D 5A}\r\n $str1 = \"/ShowWU\" ascii\r\n $str2 = \"IsWow64Process\"\r\n $str3 = \"regsvr32 \"\r\n $str4 = {8A 11 2A 55 FC 8B 45 08 88 10 8B 4D 08 8A 11 32 55 FC 8B 45 08 88 10}\r\ncondition:\r\n $mz at 0 and all of ($str*)\r\n}"
},
{
"category":"Artifacts dropped",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1421143644",
"to_ids":true,
"type":"yara",
"uuid":"54b4ee5d-a168-4453-9a4c-1d17950d210b",
"value":"rule apt_c16_win32_dropper {\r\nmeta:\r\n author = \"@dragonthreatlab\"\r\n md5 = \"ad17eff26994df824be36db246c8fb6a\"\r\n description = \"APT malware used to drop PcClient RAT\"\r\nstrings:\r\n $mz = {4D 5A}\r\n $str1 = \"clbcaiq.dll\" ascii\r\n $str2 = \"profapi_104\" ascii\r\n $str3 = \"/ShowWU\" ascii\r\n $str4 = \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\\" ascii\r\n $str5 = {8A 08 2A CA 32 CA 88 08 40 4E 75 F4 5E}\r\ncondition:\r\n $mz at 0 and all of ($str*)\r\n}"
},
{
"category":"Artifacts dropped",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1421143663",
"to_ids":true,
"type":"yara",
"uuid":"54b4ee6f-5f64-48a0-b315-4bbc950d210b",
"value":"rule apt_c16_win64_dropper {\r\nmeta:\r\n author = \"@dragonthreatlab\"\r\n md5 = \"ad17eff26994df824be36db246c8fb6a\"\r\n description = \"APT malware used to drop PcClient RAT\"\r\nstrings:\r\n $mz = {4D 5A}\r\n $str1 = \"clbcaiq.dll\" ascii\r\n $str2 = \"profapi_104\" ascii\r\n $str3 = \"\\\\Microsoft\\\\wuauclt\\\\wuauclt.dat\" ascii\r\n $str4 = {0F B6 0A 48 FF C2 80 E9 03 80 F1 03 49 FF C8 88 4A FF 75 EC}\r\ncondition:\r\n $mz at 0 and all of ($str*)\r\n}"
},
{
"category":"Artifacts dropped",
"comment":"copy/paste typo?",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487758001",
"to_ids":true,
"type":"yara",
"uuid":"54b4ee7f-b380-4792-afea-4f25950d210b",
"value":"rule apt_c16_win_disk_pcclient {\r\nmeta:\r\n author = \"@dragonthreatlab \"\r\n md5 = \"55f84d88d84c221437cd23cdbc541d2e\"\r\n description = \"Encoded version of pcclient found on disk\"\r\nstrings:\r\n $header = {51 5C 96 06 03 06 06 06 0A 06 06 06 FF FF 06 06 BE 06 06 06 06 06 06 06 46 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 EE 06 06 06 10 1F BC 10 06 BA 0D D1 25 BE 05 52 D1 25 5A 6E 6D 73 26 76 74 6F 67 74 65 71 26 63 65 70 70 6F 7A 26 64 69 26 74 79 70 26 6D 70 26 4A 4F 53 26 71 6F 6A 69 30 11 11 0C 2A 06 06 06 06 06 06 06 73 43 96 1B 37 24 00 4E 37 24 00 4E 37 24 00 4E BA 40 F6 4E 39 24 00 4E 5E 41 FA 4E 33 24 00 4E 5E 41 FC 4E 39 24 00 4E 37 24 FF 4E 0D 24 00 4E FA 31 A3 4E 40 24 00 4E DF 41 F9 4E 36 24 00 4E F6 2A FE 4E 38 24 00 4E DF 41 FC 4E 38 24 00 4E 54 6D 63 6E 37 24 00 4E 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 06 56 49 06 06 52 05 09 06 5D 87 8C 5A 06 06 06 06 06 06 06 06 E6 06 10 25 0B 05 08 06 06 1C 06 06 06 1A 06 06 06 06 06 06 E5 27 06 06 06 16 06 06 06 36 06 06 06 06 06 16 06 16 06 06 06 04 06 06 0A 06 06 06 06 06 06 06 0A 06 06 06 06 06 06 06 06 76 06 06 06 0A 06 06 06 06 06 06 04 06 06 06 06 06 16 06 06 16 06 06}\r\ncondition:\r\n $header at 0\r\n}"
},
{
"category":"Artifacts dropped",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1421143694",
"to_ids":true,
"type":"yara",
"uuid":"54b4ee8e-2328-4f8e-bff7-45ff950d210b",
"value":"rule apt_c16_win_memory_pcclient {\r\nmeta:\r\n author = \"@dragonthreatlab \"\r\n md5 = \"ec532bbe9d0882d403473102e9724557\"\r\n description = \"File matching the md5 above tends to only live in memory, hence the lack of MZ header check.\"\r\nstrings:\r\n $str1 = \"Kill You\" ascii\r\n $str2 = \"%4d-%02d-%02d %02d:%02d:%02d\" ascii\r\n $str3 = \"%4.2f KB\" ascii\r\n $encodefunc = {8A 08 32 CA 02 CA 88 08 40 4E 75 F4}\r\ncondition:\r\n all of them\r\n}"
},
{
"category":"External analysis",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1421143717",
"to_ids":false,
"type":"text",
"uuid":"54b4eea5-8ae0-403d-843f-459f950d210b",
"value":"dtl-12012015-01"
},
{
"category":"Network activity",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1421143740",
"to_ids":true,
"type":"snort",
"uuid":"54b4eebc-9548-4724-961f-4994950d210b",
"value":"alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:\"MALWARE \u00e2\u20ac\u201c DTL ID 21122014 - PcClient beacon\"; flow:established,to_server; content:\"|BB 4E 4E BC BC BC 7E 7E|\"; nocase; offset:160; depth:8; classtype:trojan-activty;)"