Windows_Trojan_Lurker_0ee51802
Description
Windows.Trojan.Lurker
Query · yara
strings:
$str1 = "\\Device\\ZHWLurker0410" wide fullword
condition:
int16(uint32(0x3C) + 0x5c) == 0x0001 and $str1
Windows.Trojan.Lurker
strings:
$str1 = "\\Device\\ZHWLurker0410" wide fullword
condition:
int16(uint32(0x3C) + 0x5c) == 0x0001 and $str1
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.