Common Information
Type Value
Value
rule Mirage_APT_Backdoor : APT Mirage Backdoor Rat MirageRat {
	meta:
		author = "Silas Cutler ( [email protected] )"
		version = "1.0"
		description = "Malware related to APT campaign"
		type = "APT Trojan / RAT / Backdoor"
	strings:
		$a1 = "welcome to the desert of the real"
		$a2 = "Mirage"
		$b = "Encoding: gzip"
		$c = /\/[A-Za-z]*\?hl=en/
	condition:
		(($a1 or $a2) or $b) and $c
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2012-09-18 96 The Mirage Campaign