Windows_Trojan_Gozi_fd494041
Description
Windows.Trojan.Gozi
Query · yara
strings:
$a1 = "/C ping localhost -n %u && del \"%s\"" wide fullword
$a2 = "/C \"copy \"%s\" \"%s\" /y && \"%s\" \"%s\"" wide fullword
$a3 = "/C \"copy \"%s\" \"%s\" /y && rundll32 \"%s\",%S\"" wide fullword
$a4 = "ASCII.GetString(( gp \"%S:\\%S\").%s))',0,0)" wide
$a5 = "filename=\"%.4u.%lu\""
$a6 = "Urundll32 \"%s\",%S" wide fullword
$a7 = "version=%u&soft=%u&user=%08x%08x%08x%08x&server=%u&id=%u&type=%u&name=%s" ascii fullword
$a8 = "%08X-%04X-%04X-%04X-%08X%04X" ascii fullword
$a9 = "&whoami=%s" ascii fullword
$a10 = "%u.%u_%u_%u_x%u" ascii fullword
$a11 = "size=%u&hash=0x%08x" ascii fullword
$a12 = "&uptime=%u" ascii fullword
$a13 = "%systemroot%\\system32\\c_1252.nls" ascii fullword
$a14 = "IE10RunOnceLastShown_TIMESTAMP" ascii fullword
condition:
8 of ($a*)