HKTL_CobaltStrike_Beacon_XOR_Strings
Description
Identifies XOR'd strings used in Cobalt Strike Beacon DLL
Query · yara
strings:
$s1 = "%02d/%02d/%02d %02d:%02d:%02d" xor(0x01-0xff)
$s2 = "Started service %s on %s" xor(0x01-0xff)
$s3 = "%s as %s\\%s: %d" xor(0x01-0xff)
$fp1 = "MalwareRemovalTool" ascii wide
$fp2 = "advanced malware removal tool" ascii wide
condition:
2 of ($s*) and not 1 of ($fp*)