Windows_Trojan_NightshadeC2_80e08aba
Description
Windows.Trojan.NightshadeC2
Query · yara
strings:
$a1 = "rundll32 \"%ws\" %ws" wide fullword
$a2 = "keylog.txt" wide fullword
$a3 = "\"%ws\" --mute-audio --do-not-de-elevate" wide fullword
$a4 = "rundll32 \"C:\\Windows\\System32\\shell32.dll\" #61" wide fullword
$a5 = "powershell Start-Sleep -Seconds 3; Remove-Item -Path %ws -Force" wide fullword
condition:
4 of them