Windows_Trojan_HiddenDriver_e26590fd
Description
Windows.Trojan.HiddenDriver
Query · yara
strings:
$activeProcessLinksOffsets = { C7 44 24 20 E8 00 00 00 C7 44 24 24 88 01 00 00 C7 44 24 28 E8 02 00 00 C7 44 24 2C F0 02 00 00 C7 44 24 30 48 04 00 00 }
$alloc_table = { 48 83 63 78 00 48 8D 8B 88 00 00 00 83 A3 80 00 00 00 00 B8 01 00 00 00 8B D0 48 89 43 68 45 33 C0 89 43 70 }
$str_0 = "InitializePsMonitor"
$str_1 = "image load notify registartion failed with code:%08x"
$str_2 = "file-system mini-filter haven't started"
$str_3 = "can't activate stealth mode"
condition:
$activeProcessLinksOffsets or $alloc_table or (all of ($str_*))