GoodToolset_pr
Description
Chinese Hacktool Set - file pr.exe
Query · yara
strings: $s1 = "-->Got WMI process Pid: %d " ascii $s2 = "-->This exploit gives you a Local System shell " ascii $s3 = "wmiprvse.exe" fullword ascii $s4 = "Try the first %d time" fullword ascii $s5 = "-->Build&&Change By p " ascii $s6 = "root\\MicrosoftIISv2" fullword wide condition: uint16(0) == 0x5a4d and filesize < 200KB and all of them