Windows_Trojan_Glupteba_70557305
Description
Windows.Trojan.Glupteba
Query · yara
strings:
$a1 = "%TEMP%\\app.exe && %TEMP%\\app.exe"
$a2 = "is unavailable%d smbtest"
$a3 = "discovered new server %s"
$a4 = "uldn't get usernamecouldn't hide servicecouldn't"
$a5 = "TERMINATE PROCESS: %ws, %d, %d" ascii fullword
$a6 = "[+] Extracting vulnerable driver as \"%ws\"" ascii fullword
condition:
all of them