Windows_Hacktool_Generic_033965e7
Description
Windows.Hacktool.Generic
Query · yara
strings:
$s_trampoline = "[DEBUG]Calling WriteProcessMemory to overwrite AddressofEntryPoint at 0x%x with trampoline: 0x%x..."
$s_overwrite = "[-]Successfully overwrote the AddressofEntryPoint"
$s_machine = "[-]Machine type UNKOWN: 0x%x"
$s_resume = "[+]Process resumed and shellcode executed"
$s_header = "[-]ReadProcessMemory completed reading %d bytes for IMAGE_OPTIONAL_HEADER"
condition:
4 of them