Windows_Trojan_SysJoker_1ef19a12
Description
Windows.Trojan.SysJoker
Query · yara
strings:
$a1 = "';Write-Output \"Time taken : $((Get - Date).Subtract($start_time).Seconds) second(s)\"" ascii fullword
$a2 = "powershell.exe Expand-Archive -LiteralPath '" ascii fullword
$a3 = "powershell.exe Invoke-WebRequest -Uri '" ascii fullword
$a4 = "\\recoveryWindows.zip" ascii fullword
condition:
3 of them