Windows_Trojan_RedLineStealer_3d9371fd
Description
Windows.Trojan.RedLineStealer
Query · yara
strings:
$a1 = "get_encrypted_key" ascii fullword
$a2 = "get_PassedPaths" ascii fullword
$a3 = "ChromeGetLocalName" ascii fullword
$a4 = "GetBrowsers" ascii fullword
$a5 = "Software\\Valve\\SteamLogin Data" wide fullword
$a6 = "%appdata%\\" wide fullword
$a7 = "ScanPasswords" ascii fullword
condition:
all of them