CN_Honker_sig_3389_3389
Description
Script from disclosed CN Honker Pentest Toolset - file 3389.vbs
Query · yara
strings:
$s1 = "success = obj.run(\"cmd /c takeown /f %SystemRoot%\\system32\\sethc.exe&echo y| " ascii /* PEStudio Blacklist: strings */
condition:
filesize < 10KB and all of them