Export from MISP
Threat Report
It’s Parliamentary: KeyBoy and the targeting of the Tibetan Community (MISP Event #17)
Threat Report
Payload delivery: CVE-2012-0158 (MISP Attribute #811)
8307e444cad98b1b59568ad2eba5f201
8307e444cad98b1b59568ad2eba5f201
CVE-2012-0158
Payload delivery: CVE-2014-4114 (MISP Attribute #832)
Vulnerability CVE-2014-4114
CVE-2014-4114
Payload delivery: CVE-2015-1641 (MISP Attribute #1374)
Vulnerability CVE-2015-1641
CVE-2015-1641
Payload type: KeyBoy (MISP Attribute #809)
KeyBoy
It’s Parliamentary: KeyBoy and the targeting of the Tibetan Community
17
2016-11-07T00:00:00+00:00
2016-11-16T15:02:57+00:00
Open
Artifacts dropped
Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)
MD5
8f08609e4e0b3d26814b3073a42df415
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)
MD5
495adb1b9777002ecfe22aaf52fcee93
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)
MD5
0c7e55509e0b6d4277b3facf864af018
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)
MD5
98977426d544bd145979f65f0322ae30
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)
MD5
c5b5f01ba24d6c02636388809f44472e
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)
MD5
371bc132499f455f06fa80696db0df27
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)
MD5
087bffa8a570079948310dc9731c5709
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)
Malware Artifacts
Host Characteristics
Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)
Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver
HKEY_CURRENT_USER
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)
SHA256
58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)
SHA256
9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)
SHA256
5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: tibetvoices.com (MISP Attribute #817)
Malware Artifacts
Domain Watchlist
Network activity: tibetvoices.com (MISP Attribute #817)
tibetvoices.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: www.about.jkub.com (MISP Attribute #823)
Malware Artifacts
Domain Watchlist
Network activity: www.about.jkub.com (MISP Attribute #823)
www.about.jkub.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: www.eleven.mypop3.org (MISP Attribute #824)
Malware Artifacts
Domain Watchlist
Network activity: www.eleven.mypop3.org (MISP Attribute #824)
www.eleven.mypop3.org
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: www.backus.myftp.name (MISP Attribute #825)
Malware Artifacts
Domain Watchlist
Network activity: www.backus.myftp.name (MISP Attribute #825)
www.backus.myftp.name
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 45.125.12.147 (MISP Attribute #815)
Malware Artifacts
IP Watchlist
Network activity: 45.125.12.147 (MISP Attribute #815)
45.125.12.147
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 103.40.102.233 (MISP Attribute #816)
Malware Artifacts
IP Watchlist
Network activity: 103.40.102.233 (MISP Attribute #816)
103.40.102.233
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 116.193.154.69 (MISP Attribute #820)
Malware Artifacts
IP Watchlist
Network activity: 116.193.154.69 (MISP Attribute #820)
116.193.154.69
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 103.242.134.243 (MISP Attribute #828)
Malware Artifacts
IP Watchlist
Network activity: 103.242.134.243 (MISP Attribute #828)
103.242.134.243
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 45.32.47.148 (MISP Attribute #829)
Malware Artifacts
IP Watchlist
Network activity: 45.32.47.148 (MISP Attribute #829)
45.32.47.148
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 157.7.84.81 (MISP Attribute #830)
Malware Artifacts
IP Watchlist
Network activity: 157.7.84.81 (MISP Attribute #830)
157.7.84.81
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 192.241.149.43 (MISP Attribute #831)
Malware Artifacts
IP Watchlist
Network activity: 192.241.149.43 (MISP Attribute #831)
192.241.149.43
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 112.10.117.47 (MISP Attribute #1880)
Malware Artifacts
IP Watchlist
Network activity: 112.10.117.47 (MISP Attribute #1880)
112.10.117.47
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)
Malware Artifacts
Malicious E-mail
Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)
tibetanparliarnent@yahoo.com
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)
Malware Artifacts
File Hash Watchlist
Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)
MD5
8307e444cad98b1b59568ad2eba5f201
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)
Malware Artifacts
File Hash Watchlist
Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)
MD5
0b4d45db323f68b465ae052d3a872068
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)
Malware Artifacts
File Hash Watchlist
Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)
MD5
beadf21b923600554b0ce54df42e78f5
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)
Malware Artifacts
File Hash Watchlist
Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)
MD5
69df3d3df4d99bc6045d073d89c68697
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)
Malware Artifacts
File Hash Watchlist
Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)
MD5
05b5cf94f07fee666eb086c91182ad25
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)
Malware Artifacts
File Hash Watchlist
Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)
MD5
8846d109b457a2ee44ddbf54d1cf7944
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)
Malware Artifacts
File Hash Watchlist
Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)
MD5
913b82ff8f090670fc6387e3a7bea12d
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)
Malware Artifacts
File Hash Watchlist
Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)
MD5
23d284245e53ae4fe05c517d807ffccf
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)
Malware Artifacts
File Hash Watchlist
Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)
SHA256
5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)
Malware Artifacts
File Hash Watchlist
Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)
SHA256
542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery
Payload delivery
Payload type
Event Threat Level: Medium
MISP Tag: TLP:AMBER
MISP Tag: SOURCE:CITIZENLAB
MISP Tag: NOTPUBLISHED
MISP Tag: DETECT
MISP Tag: TARGET:TIBETAN
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule new_keyboy_export
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("cfsUpdate")
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule new_keyboy_header_codes
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's header codes"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "*l*" wide fullword
$s2 = "*a*" wide fullword
$s3 = "*s*" wide fullword
$s4 = "*d*" wide fullword
$s5 = "*f*" wide fullword
$s6 = "*g*" wide fullword
$s7 = "*h*" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
all of them
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_commands
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's sent and received commands"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "Update" wide fullword
$s2 = "UpdateAndRun" wide fullword
$s3 = "Refresh" wide fullword
$s4 = "OnLine" wide fullword
$s5 = "Disconnect" wide fullword
$s6 = "Pw_Error" wide fullword
$s7 = "Pw_OK" wide fullword
$s8 = "Sysinfo" wide fullword
$s9 = "Download" wide fullword
$s10 = "UploadFileOk" wide fullword
$s11 = "RemoteRun" wide fullword
$s12 = "FileManager" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
6 of them
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_errors
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the sample's shell error2 log statements"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are in ASCII pre-2015 and UNICODE in 2016
$error = "Error2" ascii wide
//2016 specific:
$s1 = "Can't find [%s]!Check the file name and try again!" ascii wide
$s2 = "Open [%s] error! %d" ascii wide
$s3 = "The Size of [%s] is zero!" ascii wide
$s4 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s5 = "UploadFile [%s] Error:Connect Server Failed!" ascii wide
$s6 = "Receive [%s] Error(Recved[%d] != Send[%d])!" ascii wide
$s7 = "Receive [%s] ok! Use %2.2f seconds, Average speed %2.2f k/s" ascii wide
$s8 = "CreateThread UploadFile[%s] Error!" ascii wide
//Pre-2016:
$s9 = "Ready Download [%s] ok!" ascii wide
$s10 = "Get ControlInfo from FileClient error!" ascii wide
$s11 = "FileClient has a error!" ascii wide
$s12 = "VirtualAlloc SendBuff Error(%d)" ascii wide
$s13 = "ReadFile [%s] Error(%d)..." ascii wide
$s14 = "ReadFile [%s] Data[Readed(%d) != FileSize(%d)] Error..." ascii wide
$s15 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s16 = "RecvData MyRecv_Info Size Error!" ascii wide
$s17 = "RecvData MyRecv_Info Tag Error!" ascii wide
$s18 = "SendData szControlInfo_1 Error!" ascii wide
$s19 = "SendData szControlInfo_3 Error!" ascii wide
$s20 = "VirtualAlloc RecvBuff Error(%d)" ascii wide
$s21 = "RecvData Error!" ascii wide
$s22 = "WriteFile [%s} Error(%d)..." ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
$error and 3 of ($s*)
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_systeminfo
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the system information format before sending to C2"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are ASCII pre-2015 and UNICODE in 2016
$s1 = "SystemVersion: %s" ascii wide
$s2 = "Product ID: %s" ascii wide
$s3 = "InstallPath: %s" ascii wide
$s4 = "InstallTime: %d-%d-%d, %02d:%02d:%02d" ascii wide
$s5 = "ResgisterGroup: %s" ascii wide
$s6 = "RegisterUser: %s" ascii wide
$s7 = "ComputerName: %s" ascii wide
$s8 = "WindowsDirectory: %s" ascii wide
$s9 = "System Directory: %s" ascii wide
$s10 = "Number of Processors: %d" ascii wide
$s11 = "CPU[%d]: %s: %sMHz" ascii wide
$s12 = "RAM: %dMB Total, %dMB Free." ascii wide
$s13 = "DisplayMode: %d x %d, %dHz, %dbit" ascii wide
$s14 = "Uptime: %d Days %02u:%02u:%02u" ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
7 of them
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_related_exports
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize < 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("Embedding") or
pe.exports("SSSS") or
pe.exports("GetUP")
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_init_config_section
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the Init section where the config is stored"
date = "2016-08-28"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Payloads are normally smaller but the new dropper we spotted
//is a bit larger.
filesize < 300KB and
//Observed virtual sizes of the .Init section vary but they've
//always been 1024, 2048, or 4096 bytes.
for any i in (0..pe.number_of_sections - 1):
(
pe.sections[i].name == ".Init" and
pe.sections[i].virtual_size % 1024 == 0
)
}
!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule CVE_2012_0158_KeyBoy {
meta:
author = "Etienne Maynier <etienne@citizenlab.ca>"
description = "CVE-2012-0158 variant"
file = "8307e444cad98b1b59568ad2eba5f201"
strings:
$a = "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff09000600000000000000000000000100000001" nocase // OLE header
$b = "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" nocase // junk data
$c = /5(\{\\b0\}|)[ ]*2006F00(\{\\b0\}|)[ ]*6F007(\{\\b0\}|)[ ]*400200045(\{\\b0\}|)[ ]*006(\{\\b0\}|)[ ]*E007(\{\\b0\}|)[ ]*400720079/ nocase
$d = "MSComctlLib.ListViewCtrl.2"
$e = "ac38c874503c307405347aaaebf2ac2c31ebf6e8e3" nocase //decoding shellcode
condition:
all of them
}
!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule keyboy_exploit_doc_meta{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the meta associated with these exploit docs"
date = "2016-09-30"
strings:
$role = "{\\author Master}{\\operator Master}"
$creatim = "{\\creatim\\yr2015\\mo10\\dy16\\hr11\\min37}"
$revtim = "{\\revtim\\yr2015\\mo10\\dy16\\hr13\\min54}"
condition:
uint32be(0) == 0x7B5C7274 and
filesize < 1MB and
all of them
}
citizenlab
../../../descendant-or-self::node()