Windows_Trojan_MassLogger_511b001e
Description
Windows.Trojan.MassLogger
Query · yara
strings:
$a1 = "ExecutionPolicy Bypass -WindowStyle Hidden -Command netsh advfirewall firewall add rule name='allow RemoteDesktop' dir=in protoc" wide
$a2 = "https://raw.githubusercontent.com/lisence-system/assemply/main/VMprotectEncrypt.jpg" wide fullword
$a3 = "ECHO $SMTPServer = smtp.gmail.com >> %PSScript%" wide fullword
$a4 = "Injecting Default Template...." wide fullword
$a5 = "GetVncLoginMethodAsync" ascii fullword
$a6 = "/c start computerdefaults.exe" wide fullword
condition:
all of them