Windows_Trojan_RoningLoader_a4e851ac
Description
Windows.Trojan.RoningLoader
Query · yara
strings:
$binary0 = { 48 89 45 80 8B 05 C5 E8 0C 00 48 0F 47 4C 24 70 66 89 04 51 48 8D 44 24 70 66 44 89 6C 51 02 }
$str0 = "Successfully created PPL process with PID: " wide fullword
$str1 = "C:\\Windows\\System32\\ClipUp.exe" wide fullword
$str2 = "regsvr32.exe /S"
condition:
$binary0 or all of ($str*)