Windows_Trojan_FinalDraft_ce03cf22
Description
Windows.Trojan.FinalDraft
Query · yara
strings:
$seq_derive_encryption_key = { 4D 6B C0 1F 48 0F BE 02 4C 03 C0 48 03 D7 49 3B D2 }
$seq_decrypt_configuration = { 48 8B ?? 83 E0 ?? [4-9] 30 04 0A 48 [2] 48 81 ?? 9A 14 00 00 72 }
$seq_magic = { 12 34 AB CD FF FF CD AB 34 12 }
$str_injection_target_0 = "%c:\\Windows\\SysWOW64\\mspaint.exe" fullword
$str_injection_target_1 = "%c:\\Windows\\System32\\mspaint.exe" fullword
$str_injection_target_2 = "%c:\\Windows\\SysWOW64\\conhost.exe" fullword
$str_injection_target_3 = "%c:\\Windows\\System32\\conhost.exe" fullword
$str_active_connections_fmt_str = "%-7s%-34s%-34s%-13s%-7s" fullword
$str_graph_parameters = "client_id=d3590ed6-52b3-4102-aeff-aad2292ab01c&grant_type=refresh" fullword
$str_err_code = "err code: 0x%08x" fullword
condition:
5 of them