Windows_Trojan_MetaStealer_f94e2464
Description
Windows.Trojan.MetaStealer
Query · yara
strings:
$string1 = "AvailableLanguages" fullword
$string2 = "GetGraphicCards" fullword
$string3 = "GetVs" fullword
$string4 = "GetSerialNumber" fullword
$string5 = "net.tcp://" wide
$string6 = "AntivirusProduct|AntiSpyWareProduct|FirewallProduct" wide
$string7 = "wallet.dat" wide
$string8 = "[A-Za-z\\d]{24}\\.[\\w-]{6}\\.[\\w-]{27}" wide
$string9 = "Software\\Valve\\Steam" wide
$string10 = "{0}\\FileZilla\\recentservers.xml" wide
$string11 = "{0}\\FileZilla\\sitemanager.xml" wide
$string12 = "([a-zA-Z0-9]{1000,1500})" wide
$string13 = "\\qemu-ga.exe" wide
$string14 = "metaData" wide
$string15 = "%DSK_23%" wide
$string16 = "CollectMemory" fullword
condition:
all of them