Windows_Trojan_MyloBot_a895174a
Description
Windows.Trojan.MyloBot
Query · yara
strings:
$a1 = "%s\\%s.lnk" wide fullword
$a2 = "%s\\%s.exe" wide fullword
$a3 = "%s\\%s\\%s.exe" wide fullword
$a4 = "HTTP/1.0 502" ascii fullword
$a5 = "/c \"%ws '%ws%s'\"" ascii fullword
$a6 = ">> %ws %ws %ws" ascii fullword
$a7 = "%s\\DefaultIcon" ascii fullword
condition:
all of them