CN_Tools_xsniff
Description
Chinese Hacktool Set - file xsniff.exe
Query · yara
strings: $s0 = "xsiff.exe -pass -hide -log pass.log" fullword ascii $s1 = "HOST: %s USER: %s, PASS: %s" fullword ascii $s2 = "xsiff.exe -tcp -udp -asc -addr 192.168.1.1" fullword ascii $s10 = "Code by glacier <glacier@xfocus.org>" fullword ascii $s11 = "%-5s%s->%s Bytes=%d TTL=%d Type: %d,%d ID=%d SEQ=%d" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 220KB and 2 of them