Windows_Trojan_XtremeRAT_cd5b60be
Description
Windows.Trojan.XtremeRAT
Query · yara
strings:
$s01 = "SOFTWARE\\XtremeRAT" wide fullword
$s02 = "XTREME" wide fullword
$s03 = "STARTSERVERBUFFER" wide fullword
$s04 = "ENDSERVERBUFFER" wide fullword
$s05 = "ServerKeyloggerU" ascii fullword
$s06 = "TServerKeylogger" ascii fullword
$s07 = "XtremeKeylogger" wide fullword
$s08 = "XTREMEBINDER" wide fullword
$s09 = "UnitInjectServer" ascii fullword
$s10 = "shellexecute=" wide fullword
condition:
7 of ($s*)