Windows_Trojan_Matanbuchus_b521801b
Description
Windows.Trojan.Matanbuchus
Query · yara
strings:
$a1 = "%PROCESSOR_ARCHITECTURE%" ascii fullword
$a2 = "%PROCESSOR_REVISION%\\" ascii fullword
$a3 = "%LOCALAPPDATA%\\" ascii fullword
$a4 = "\"C:\\Windows\\system32\\schtasks.exe\" /Create /SC MINUTE /MO 1 /TN" ascii fullword
condition:
all of them