Malware_QA_tls
Description
VT Research QA uploaded malware - file tls.exe
Query · yara
strings: $s1 = "\\funoverip\\ultimate-payload-template1\\" ascii $s2 = "ULTIMATEPAYLOADTEMPLATE1" fullword wide $s3 = "ultimate-payload-template1" fullword wide condition: ( uint16(0) == 0x5a4d and filesize < 300KB and 1 of them ) or ( all of them )