Windows_Trojan_Danabot_6f3dadb2
Description
Windows.Trojan.Danabot
Query · yara
strings:
$a1 = "%s.dll" ascii fullword
$a2 = "del_ini://Main|Password|" wide fullword
$a3 = "S-Password.txt" wide fullword
$a4 = "BiosTime:" wide fullword
$a5 = "%lu:%s:%s:%d:%s" ascii fullword
$a6 = "DNS:%s" ascii fullword
$a7 = "THttpInject&" ascii fullword
$a8 = "TCookies&" ascii fullword
condition:
all of them