Skip to content

MiniDionis VBS Dropped File Hash - Detect

ID: minidionis-vbs-malware-hash

Severity: info

Author: pussycat0x

Tags: malware,minidionis

Detect Dropped File - 1.vbs

id: minidionis-vbs-malware-hash
info:
name: MiniDionis VBS Dropped File Hash - Detect
author: pussycat0x
severity: info
description: Detect Dropped File - 1.vbs
reference:
- https://malwr.com/analysis/ZDc4ZmIyZDI4MTVjNGY5NWI0YzE3YjIzNGFjZTcyYTY/
- https://github.com/Yara-Rules/rules/blob/master/malware/APT_Minidionis.yar
tags: malware,minidionis
file:
- extensions:
- all
matchers:
- type: dsl
dsl:
- "sha256(raw) == '97dd1ee3aca815eb655a5de9e9e8945e7ba57f458019be6e1b9acb5731fa6646'"
# digest: 4a0a00473045022100a0db42d007585c49af3559027ade765d94bb190334a45d4a9f20a97afd2acfa1022030bcae722205b0e39c0093be3c292d4e61e035e807ec4fa085ed68375ce53b6c:922c64590222798bb761d5b6d8e72950

This template is used to detect vulnerabilities in web applications. It can be used with the Nuclei tool to scan for specific patterns or behaviors.

Terminal window
$ nuclei -u "URL" -t "file/malware/hash/minidionis-vbs-malware-hash.yaml"

View on Github