Windows_Hacktool_Generic_42e0be24
Description
Windows.Hacktool.Generic
Query · yara
strings:
$s_load = "[DEBUG]Loading VirtualAlloc, VirtualProtect and RtlCopyMemory procedures"
$s_copy = "[DEBUG]Copying shellcode to memory with RtlCopyMemory"
$s_protect = "[DEBUG]Calling VirtualProtect to change memory region to PAGE_EXECUTE_READ"
$s_decode = "[!]there was an error decoding the string to a hex byte array: %s"
$s_done = "[-]Shellcode memory region changed to PAGE_EXECUTE_READ"
condition:
4 of them