RemoteExec_Tool
Description
Remote Access Tool used in APT Terracotta
Query · yara
strings: $s0 = "cmd.exe /q /c \"%s\"" fullword ascii $s1 = "\\\\.\\pipe\\%s%s%d" fullword ascii $s2 = "This is a service executable! Couldn't start directly." fullword ascii $s3 = "\\\\.\\pipe\\TermHlp_communicaton" fullword ascii $s4 = "TermHlp_stdout" fullword ascii $s5 = "TermHlp_stdin" fullword ascii condition: uint16(0) == 0x5a4d and filesize < 75KB and 4 of ($s*)