Windows_Hacktool_SharpUp_e5c87c9a
Description
Windows.Hacktool.SharpUp
Query · yara
strings:
$guid = "FDD654F5-5C54-4D93-BF8E-FAF11B00E3E9" ascii wide nocase
$str0 = "^\\W*([a-z]:\\\\.+?(\\.exe|\\.bat|\\.ps1|\\.vbs))\\W*" ascii wide
$str1 = "^\\W*([a-z]:\\\\.+?(\\.exe|\\.dll|\\.sys))\\W*" ascii wide
$str2 = "SELECT * FROM win32_service WHERE Name LIKE '{0}'" ascii wide
$print_str1 = "[!] Modifialbe scheduled tasks were not evaluated due to permissions." ascii wide
$print_str2 = "[+] Potenatially Hijackable DLL: {0}" ascii wide
$print_str3 = "Registry AutoLogon Found" ascii wide
condition:
$guid or (all of ($str*) and 1 of ($print_str*))