MAL_Trickbot_Oct19_4
Description
Detects Trickbot malware
Query · yara
strings:
$x1 = "c:\\users\\user\\documents\\visual studio 2005\\projects\\adzxser\\release\\ADZXSER.pdb" fullword ascii
$x2 = "http://root-hack.org" fullword ascii
$x3 = "http://hax-studios.net" fullword ascii
$x4 = "5OCFBBKCAZxWUE#$_SVRR[SQJ" fullword ascii
$x5 = "G*\\AC:\\Users\\911\\Desktop\\cButtonBar\\cButtonBar\\ButtonBar.vbp" fullword wide
condition:
uint16(0) == 0x5a4d and filesize <= 2000KB and 1 of them