OracleScan
Description
Chinese Hacktool Set - file OracleScan.exe
Query · yara
strings: $s1 = "MYBLOG:HTTP://HI.BAIDU.COM/0X24Q" fullword ascii $s2 = "\\Borland\\Delphi\\RTL" ascii $s3 = "USER_NAME" ascii $s4 = "FROMWWHERE" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 300KB and all of them