Windows_Trojan_AveMaria_e01305a0
Description
Windows.Trojan.AveMaria
Query · yara
strings:
$a = "SOFTWARE\\_rptls" wide fullword
$b = "-w %ws -d C -f %s" fullword
$c = "RDPClip" wide fullword
$d = "ExplorerIdentifier" wide fullword
$e = "WM_FIND" wide fullword
$f = "WM_DISP" wide fullword
$g = "MsgBox.exe" wide fullword
$h = "Hey I'm Admin" wide fullword
$i = "/n:%temp%\\ellocnak.xml" wide fullword
$j = "CommandHandler::handleStartVncCommand() Start VNC on port : %d" wide fullword
condition:
7 of them