Windows_Trojan_AveMaria_31d2bce9
Description
Windows.Trojan.AveMaria
Query · yara
strings:
$a1 = "cmd.exe /C ping 1.2.3.4 -n 2 -w 1000 > Nul & Del /f /q " ascii fullword
$a2 = "SMTP Password" wide fullword
$a3 = "select signon_realm, origin_url, username_value, password_value from logins" ascii fullword
$a4 = "Elevation:Administrator!new:{3ad05575-8857-4850-9277-11b85bdb8e09}" wide fullword
$a5 = "for /F \"usebackq tokens=*\" %%A in (\"" wide fullword
$a6 = "\\Torch\\User Data\\Default\\Login Data" wide fullword
$a7 = "/n:%temp%\\ellocnak.xml" wide fullword
$a8 = "\"os_crypt\":{\"encrypted_key\":\"" wide fullword
$a9 = "Hey I'm Admin" wide fullword
$a10 = "\\logins.json" wide fullword
$a11 = "Accounts\\Account.rec0" ascii fullword
$a12 = "warzone160" ascii fullword
$a13 = "Ave_Maria Stealer OpenSource github Link: https://github.com/syohex/java-simple-mine-sweeper" wide fullword
condition:
8 of ($a*)