CN_Hacktool_S_EXE_Portscanner
Description
Detects a chinese Portscanner named s.exe
Query · yara
strings:
$s0 = "\\Result.txt" ascii
$s1 = "By:ZT QQ:376789051" fullword ascii
$s2 = "(http://www.eyuyan.com)" fullword wide
condition:
all of them