FourElementSword_ResN32DLL
Description
Detects FourElementSword Malware
Query · yara
strings: $s1 = "\\Release\\BypassUAC.pdb" ascii $s2 = "\\ResN32.dll" wide $s3 = "Eupdate" fullword wide condition: all of them
Detects FourElementSword Malware
strings: $s1 = "\\Release\\BypassUAC.pdb" ascii $s2 = "\\ResN32.dll" wide $s3 = "Eupdate" fullword wide condition: all of them
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.