Fidelis_Advisory_cedt370
Description
Detects a string found in memory of malware cedt370r(3).exe
Query · yara
strings:
$s0 = "PO.exe" ascii fullword
$s1 = "Important.exe" ascii fullword
$s2 = "&username=" ascii fullword
$s3 = "Browsers.txt" ascii fullword
condition:
all of them