CN_Honker_windows_exp
Description
Sample from CN Honker Pentest Toolset - file exp.exe
Query · yara
strings: $s0 = "c:\\windows\\system32\\command.com /c " fullword ascii /* PEStudio Blacklist: strings */ $s8 = "OH,Sry.Too long command." fullword ascii /* PEStudio Blacklist: strings */ condition: uint16(0) == 0x5a4d and filesize < 220KB and all of them