Windows_Trojan_Oyster_6aa9dba8
Description
Windows.Trojan.Oyster
Query · yara
strings:
$a = "\", \"b4\":\"" wide fullword
$b = "C:\\Windows\\System32\\rundll32.exe \"" wide fullword
$c = "api/kcehc" wide fullword
$d = "api/jgfnsfnuefcnegfnehjbfncejfh" wide fullword
$e = { C6 45 ?? 0A 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 C6 45 ?? 0B 8D 86 ?? ?? ?? ?? 50 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 68 ?? ?? ?? ?? 8B D0 C6 45 ?? 0C 8D 8D ?? ?? ?? ?? E8 ?? ?? ?? ?? 8B D0 8D 46 ?? C6 45 ?? 0D }
$f = "Unknown ext file start" wide fullword
condition:
4 of them