Windows_Trojan_Generic_9997489c
Description
Windows.Trojan.Generic
Query · yara
strings:
$ldrload_dll = { 43 6A 45 9E }
$loadlibraryw = { F1 2F 07 B7 }
$ntallocatevirtualmemory = { EC B8 83 F7 }
$ntcreatethreadex = { B0 CF 18 AF }
$ntqueryinformationprocess = { C2 5D DC 8C }
$ntprotectvirtualmemory = { 88 28 E9 50 }
$ntreadvirtualmemory = { 03 81 28 A3 }
$ntwritevirtualmemory = { 92 01 17 C3 }
$rtladdvectoredexceptionhandler = { 89 6C F0 2D }
$rtlallocateheap = { 5A 4C E9 3B }
$rtlqueueworkitem = { 8E 02 92 AE }
$virtualprotect = { 0D 50 57 E8 }
condition:
4 of them