Windows_Hacktool_Phant0m_2d6f9b57
Description
Windows.Hacktool.Phant0m
Query · yara
strings:
$api = "NtQueryInformationThread"
$s1 = "Suspending EventLog thread %d with start address %p"
$s2 = "Found the EventLog Module (wevtsvc.dll) at %p"
$s3 = "Event Log service PID detected as %d."
$s4 = "Thread %d is detected and successfully killed."
$s5 = "Windows EventLog module %S at %p"
condition:
$api and 2 of ($s*)