Windows_Trojan_Bumblebee_70bed4f3
Description
Windows.Trojan.Bumblebee
Query · yara
strings:
$a1 = "Checking Virtual PC processes %s " wide fullword
$a2 = "SELECT * FROM Win32_ComputerSystemProduct" ascii fullword
$a3 = "Injection-Date" ascii fullword
$a4 = " -Command \"Wait-Process -Id " ascii fullword
$a5 = "%WINDIR%\\System32\\wscript.exe" wide fullword
$a6 = "objShell.Run \"rundll32.exe my_application_path"
$a7 = "Checking reg key HARDWARE\\Description\\System - %s is set to %s" wide fullword
condition:
5 of them