Windows_Trojan_Winos_464b8a2e
Description
Windows.Trojan.Winos
Query · yara
strings:
$a1 = "CLSID\\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}" wide fullword
$a2 = "d33f351a4aeea5e608853d1a56661059" wide fullword
$a3 = "%s-%04d%02d%02d-%02d%02d%02d.dmp" wide fullword
$a4 = "Windows\\System32\\tracerpt.exe" wide fullword
$a5 = "Software\\Tencent\\Plugin\\VAS" wide fullword
$a6 = "onlyloadinmyself" wide fullword
$a7 = "IpDatespecial" wide fullword
$a8 = "IpDates_info" wide fullword
$a9 = "Console\\0" wide fullword
$a10 = "Console\\1" wide fullword
condition:
4 of them