MAL_Katz_Stealer_May25
Description
Detects Katz stealer
Query · yara
strings:
$s1 = "Motherboard Product: %s" ascii
$s2 = "cmd.exe /c %s" ascii
$s3 = "reg export \"%s\" \"%s\" /y" ascii
$s4 = ").request({ hostname: '" ascii
$s5 = "Type: Removable"
$s6 = "%s\\Microsoft\\Windows Live Mail" ascii
condition:
uint16(0) == 0x5a4d
and filesize < 300KB
and 4 of them