Windows_Trojan_SystemBC_c1b58c2f
Description
Windows.Trojan.SystemBC
Query · yara
strings:
$a1 = "GET %s HTTP/1.0" ascii fullword
$a2 = "HOST1:"
$a3 = "PORT1:"
$a4 = "-WindowStyle Hidden -ep bypass -file \"" ascii fullword
$a5 = "BEGINDATA" ascii fullword
$a6 = "socks32.dll" ascii fullword
condition:
5 of them