SHARE
TWEET

Agenttesla new yara

James_inthe_box Jan 21st, 2019 296 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. rule Agenttesla_new_bin_mem
  2. {
  3.     meta:
  4.     author = "James_inthe_box"
  5.     reference = "https://app.any.run/tasks/7d26c900-f772-4697-8bec-0c24f29e317c"
  6.     date = "2019/01"
  7.     maltype = "Infotealer"
  8.  
  9.     strings:
  10.         $string1 = "Password could not decrypted." wide
  11.     $string2 = "hostname|encryptedPassword|encryptedUsername" wide
  12.     $string3 = "firefox.exe" wide
  13.     $string4 = "IELibrary.dll"
  14.     $string5 = "PROGRAMFILES" wide
  15.    
  16.     condition:
  17.         all of ($string*)
  18. }
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top