Windows_Trojan_MicroBackdoor_46f2e5fd
Description
Windows.Trojan.MicroBackdoor
Query · yara
strings:
$a1 = "cmd.exe /C \"%s%s\"" wide fullword
$a2 = "%s|%s|%d|%s|%d|%d" wide fullword
$a3 = "{{{$%.8x}}}" ascii fullword
$a4 = "30D78F9B-C56E-472C-8A29-E9F27FD8C985" ascii fullword
$a5 = "chcp 65001 > NUL & " wide fullword
$a6 = "CONNECT %s:%d HTTP/1.0" ascii fullword
condition:
5 of them