FreeVersion_debug
Description
Chinese Hacktool Set - file debug.exe
Query · yara
strings: $s0 = "c:\\Documents and Settings\\Administrator\\" ascii $s1 = "Got WMI process Pid: %d" ascii $s2 = "This exploit will execute" ascii $s6 = "Found token %s " ascii $s7 = "Running reverse shell" ascii $s10 = "wmiprvse.exe" fullword ascii $s12 = "SELECT * FROM IIsWebInfo" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 820KB and 3 of them