Windows_Trojan_TCLBanker_5df0f971
Description
Windows.Trojan.TCLBanker
Query · yara
strings:
$s1 = "[Persistence] EnsureInstalled: exe=" wide fullword
$s2 = "[Persistence] Task deleted OK" wide fullword
$s3 = "CommandLine FROM Win32_Process WHERE Name = 'msedge.exe'" wide fullword
$s4 = "KeyloggerHookThread" wide fullword
$s5 = "Fique atento ao telefone informado" wide fullword
$s6 = "O telefone deve ter 10" wide fullword
$s7 = "Trabalhando em atualizacoes" wide fullword
$s8 = "Win32_Process.Create falhou com codigo" wide fullword
condition:
4 of them