ms10048_x86
Description
Chinese Hacktool Set - file ms10048-x86.exe
Query · yara
strings: $s1 = "[ ] Resolving PsLookupProcessByProcessId" fullword ascii $s2 = "The target is most likely patched." fullword ascii $s3 = "Dojibiron by Ronald Huizer, (c) master@h4cker.us ." fullword ascii $s4 = "[ ] Creating evil window" fullword ascii $s5 = "%sHANDLEF_INDESTROY" fullword ascii $s6 = "[+] Set to %d exploit half succeeded" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 100KB and 4 of them