Windows_Trojan_Bughatch_98f3c0be
Description
Windows.Trojan.Bughatch
Query · yara
strings:
$a1 = "-windowstyle hidden -executionpolicy bypass -file"
$a2 = "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe"
$a3 = "ReflectiveLoader"
$a4 = "\\Sysnative\\"
$a5 = "TEMP%u.CMD"
$a6 = "TEMP%u.PS1"
$a7 = "\\TEMP%d.%s"
$a8 = "NtSetContextThread"
$a9 = "NtResumeThread"
condition:
6 of them