Windows_Trojan_SystemBC_5e883723
Description
Windows.Trojan.SystemBC
Query · yara
strings:
$a1 = "GET /tor/rendezvous2/%s HTTP/1.0" ascii fullword
$a2 = "https://api.ipify.org/" ascii fullword
$a3 = "KEY-----" ascii fullword
$a4 = "Host: %s" ascii fullword
$a5 = "BEGINDATA" ascii fullword
$a6 = "-WindowStyle Hidden -ep bypass -file \"" ascii fullword
condition:
all of them