Windows_Trojan_Cryptbot_489a6562
Description
Windows.Trojan.Cryptbot
Query · yara
strings:
$a1 = "/c rd /s /q %Temp%\\" wide fullword
$a2 = "\\_Files\\_AllPasswords_list.txt" wide fullword
$a3 = "\\files_\\cryptocurrency\\log.txt" wide fullword
$a4 = "%wS\\%wS\\%wS.tmp" wide fullword
$a5 = "%AppData%\\waves-exchange" wide fullword
condition:
all of them