Windows_Trojan_Asyncrat_11a11ba1
Description
Windows.Trojan.Asyncrat
Query · yara
strings:
$a1 = "/c schtasks /create /f /sc onlogon /rl highest /tn \"" wide fullword
$a2 = "Stub.exe" wide fullword
$a3 = "get_ActivatePong" ascii fullword
$a4 = "vmware" wide fullword
$a5 = "\\nuR\\noisreVtnerruC\\swodniW\\tfosorciM\\erawtfoS" wide fullword
$a6 = "get_SslClient" ascii fullword
condition:
all of them