CN_Honker_Interception
Description
Sample from CN Honker Pentest Toolset - file Interception.exe
Query · yara
strings: $s2 = ".\\dat\\Hookmsgina.dll" fullword ascii /* PEStudio Blacklist: strings */ $s5 = "WinlogonHackEx " fullword wide /* PEStudio Blacklist: strings */ condition: uint16(0) == 0x5a4d and filesize < 160KB and all of them