DeepPanda_Trojan_Kakfum
Description
Hack Deep Panda - Trojan.Kakfum sqlsrv32.dll
Query · yara
strings: $s0 = "%SystemRoot%\\System32\\svchost.exe -k sqlserver" fullword ascii $s1 = "%s\\sqlsrv32.dll" fullword ascii $s2 = "%s\\sqlsrv64.dll" fullword ascii $s3 = "%s\\%d.tmp" fullword ascii $s4 = "ServiceMaix" fullword ascii $s15 = "sqlserver" fullword ascii condition: all of them