Windows_Trojan_JesterStealer_b35c6f4b
Description
Windows.Trojan.JesterStealer
Query · yara
strings:
$a1 = "[Decrypt Chrome Password] {0}" wide fullword
$a2 = "Passwords.txt" wide fullword
$a3 = "9Stealer.Recovery.FTP.FileZilla+<EnumerateCredentials>d__0" ascii fullword
$a4 = "/C chcp 65001 && ping 127.0.0.1 && DEL /F /S /Q /A \"" wide fullword
$a5 = "citigroup.com" wide fullword
$a6 = "Password: {1}" wide fullword
$a7 = "set_steamLogin" ascii fullword
condition:
5 of them