FourElementSword_Config_File
Description
Detects FourElementSword Malware
Query · yara
strings: $s0 = "01,,hccutils.dll,2" fullword ascii $s1 = "RegisterDlls=OurDll" fullword ascii $s2 = "[OurDll]" fullword ascii $s3 = "[DefaultInstall]" fullword ascii /* Goodware String - occured 16 times */ $s4 = "Signature=\"$Windows NT$\"" fullword ascii /* Goodware String - occured 26 times */ condition: 4 of them