Windows_Trojan_Azorult_38fce9ea
Description
Windows.Trojan.Azorult
Query · yara
strings:
$a1 = "/c %WINDIR%\\system32\\timeout.exe 3 & del \"" wide fullword
$a2 = "%APPDATA%\\.purple\\accounts.xml" wide fullword
$a3 = "%TEMP%\\curbuf.dat" wide fullword
$a4 = "PasswordsList.txt" ascii fullword
$a5 = "Software\\Valve\\Steam" wide fullword
condition:
all of them