MAL_Trickbot_Oct19_2
Description
Detects Trickbot malware
Query · yara
strings:
$x1 = "C:\\Users\\User\\Desktop\\Encrypt\\Math_Cad\\Release\\Math_Cad.pdb" fullword ascii
$x2 = "AxedWV3OVTFfnGb" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize <= 2000KB and 1 of them