Windows_Trojan_Vidar_65d3d7e5
Description
Windows.Trojan.Vidar
Query · yara
strings:
$str_1 = "avghooka.dll" wide fullword
$str_2 = "api_log.dll" wide fullword
$str_3 = "babyfox.dll" ascii fullword
$str_4 = "vksaver.dll" ascii fullword
$str_5 = "delays.tmp" wide fullword
$str_6 = "\\Monero\\wallet.keys" ascii fullword
$str_7 = "wallet_path" ascii fullword
$str_8 = "Hong Lee" ascii fullword
$str_9 = "milozs" ascii fullword
condition:
6 of them