Windows_Trojan_Diceloader_b32c6b99
Description
Windows.Trojan.Diceloader
Query · yara
strings:
$a1 = "D$0GET " ascii fullword
$a2 = "D$THostf" ascii fullword
$a3 = "D$,POST" ascii fullword
$a4 = "namef" ascii fullword
$a5 = "send" ascii fullword
$a6 = "log.ini" wide
$a7 = { 70 61 73 73 00 00 65 6D 61 69 6C 00 00 6C 6F 67 69 6E 00 00 73 69 67 6E 69 6E 00 00 61 63 63 6F 75 6E 74 00 00 70 65 72 73 69 73 74 65 6E 74 00 00 48 6F 73 74 3A 20 }
condition:
all of them