MAL_Trickbot_Oct19_6
Description
Detects Trickbot malware
Query · yara
strings:
$x1 = "D:\\MyProjects\\spreader\\Release\\ssExecutor_x86.pdb" fullword ascii
$s1 = "%s\\appdata\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\%s" fullword ascii
$s2 = "%s\\appdata\\roaming\\%s" fullword ascii
$s3 = "WINDOWS\\SYSTEM32\\TASKS" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize <= 400KB and ( 1 of ($x*) or 3 of them )