Actor(s): TA410
There is no description at this point.
rule win_tendyron_dropper_w0 { meta: description = "TA410 Tendyron Dropper" reference = "https://www.welivesecurity.com/" source = "https://github.com/eset/malware-ioc/" license = "BSD 2-Clause" version = "1" author = "ESET Research" date = "2020-12-09" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tendyron_dropper" malpedia_rule_date = "20251015" malpedia_hash = "" malpedia_version = "20251015" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $s1 = "Global\\{F473B3BE-08EE-4710-A727-9E248F804F4A}" wide $s2 = "Global\\8D32CCB321B2" wide $s3 = "Global\\E4FE94F75490" wide $s4 = "Program Files (x86)\\Internet Explorer\\iexplore.exe" wide $s5 = "\\RPC Control\\OLE" wide $s6 = "ALPC Port" wide condition: int16(0) == 0x5A4D and 4 of them }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY