Windows_Trojan_PureLogsStealer_8ea443f9
Description
Windows.Trojan.PureLogsStealer
Query · yara
strings:
$str1 = "SendDiscordAsync" ascii fullword
$str2 = "SendCryptoWalletAsync" ascii fullword
$str3 = "CollectAndSendAllAsync" ascii fullword
$str4 = "/filesearch/req" wide fullword
$str5 = "/filesearch/res" wide fullword
$str6 = "/chunk/data" wide fullword
$str7 = "/chunk/start" wide fullword
condition:
3 of them