Windows_Trojan_Clipbanker_7efaef9f
Description
Windows.Trojan.Clipbanker
Query · yara
strings:
$a1 = "C:\\Users\\youar\\Desktop\\Allcome\\Source code\\Build\\Release\\Build.pdb" ascii fullword
$b1 = "https://steamcommunity.com/tradeoffer" ascii fullword
$b2 = "/Create /tn NvTmRep_CrashReport3_{B2FE1952-0186} /sc MINUTE /tr %s" ascii fullword
$b3 = "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0" ascii fullword
$b4 = "ProcessHacker.exe" ascii fullword
condition:
all of them