Windows_Trojan_Rhadamanthys_1da1c2c2
Description
Windows.Trojan.Rhadamanthys
Query · yara
strings:
$a1 = "%s\\tdata\\key_datas" wide fullword
$a2 = "\\config\\loginusers.vdf" wide fullword
$a3 = "/bin/KeePassHax.dll" ascii fullword
$a4 = "%%APPDATA%%\\ns%04x.dll" wide fullword
$a5 = "\\\\.\\pipe\\{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}" wide fullword
$a6 = " /s /n /i:\"%s,%u,%u,%u\" \"%s\"" wide fullword
$a7 = "strbuf(%lx) reallocs: %d, length: %d, size: %d" ascii fullword
$a8 = "SOFTWARE\\FTPWare\\CoreFTP\\Sites\\%s" wide fullword
condition:
6 of them