Windows_Trojan_Njrat_30f3c220
Description
Windows.Trojan.Njrat
Query · yara
strings:
$a1 = "get_Registry" ascii fullword
$a2 = "SEE_MASK_NOZONECHECKS" wide fullword
$a3 = "Download ERROR" wide fullword
$a4 = "cmd.exe /c ping 0 -n 2 & del \"" wide fullword
$a5 = "netsh firewall delete allowedprogram \"" wide fullword
$a6 = "[+] System : " wide fullword
condition:
3 of them