DefenderYara/TrojanClicker/Win32/Yumud/TrojanClicker_Win32_Yumud_A...

13 lines
667 B
Plaintext

rule TrojanClicker_Win32_Yumud_A{
meta:
description = "TrojanClicker:Win32/Yumud.A,SIGNATURE_TYPE_PEHSTR_EXT,0b 00 0b 00 03 00 00 0a 00 "
strings :
$a_03_0 = {db 45 fc dd 5d ec dd 45 ec db 45 f8 dd 5d e4 dc 65 e4 dd 5d dc dd 45 dc dc 05 90 01 04 dd 5d d4 dd 45 d4 e8 90 00 } //01 00
$a_00_1 = {75 72 6c 00 00 68 74 74 70 3a 2f 2f 00 2f 73 3f 00 2f 62 61 69 64 75 3f 00 74 69 74 6c 65 00 3f 71 75 65 72 79 3d 00 2f 00 68 74 74 70 3a 2f 2f 77 77 77 2e } //01 00
$a_00_2 = {75 72 6c 00 00 68 74 74 70 3a 2f 2f 00 2f 73 3f 00 2f 62 61 69 64 75 3f 00 3f 71 75 65 72 79 3d 00 2f 00 68 74 74 70 3a 2f 2f 77 77 77 2e } //00 00
condition:
any of ($a_*)
}