Windows_Trojan_PathLoader_d62822f8
Description
Windows.Trojan.PathLoader
Query · yara
strings:
$debug_str = "[-] WinHttpSendRequest %d\n" ascii fullword
$fnv_GetProcAddress = { 44 69 D2 93 01 00 01 45 84 C0 75 D4 41 81 FA 0C B5 82 01 }
$peb_GetTickCount = { 48 3D 60 EA 00 00 0F 8F ?? ?? ?? ?? 65 48 8B 04 25 60 00 00 00 48 8B 40 18 48 8B 40 10 }
$base64_http = { 36 31 34 38 35 32 33 30 36 33 34 }
condition:
3 of them