PepperPotts

fox stealer yara

May 7th, 2019
455
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.95 KB | None | 0 0
  1. rule fox_stealer_mem
  2. {
  3. strings:
  4. $a1="aHR0cDovLw==" wide
  5. $a2="TW96aWxsYS81LjAgKFdpbmRvd3MgTlQgNi4xOyBXaW42NDsgeDY0KSBBcHBsZVdlYktpdC81MzcuMzYgKEtIVE1MLCBsaWtlIEdlY2tvKSBDaHJvbWUvNjQuMC4zMjgyLjExOSBTYWZhcmkvNTM3LjM2" wide
  6. $a3="L2xpc3QucGhw" wide
  7. $a4="L3Bvc3QucGhw" wide
  8. $a5="My Own Capture Window" wide
  9. $a6="MY_ATOM_FOR_CONTROL" wide
  10. $a7="\\Lists\\InfoPC.txt" wide
  11. $b1="\\Lists\\Password.txt" wide
  12. $b2="\\Lists\\Cookies" wide
  13. $b3="\\Lists\\Autofill.txt" wide
  14. $b4="\\Lists\\Steam\\config" wide
  15. $b5="\\Steam\\config" wide
  16. $b6="Telegram Desktop\\tdata" wide
  17. $b7="\\Lists\\screenshot" wide
  18. $b8="netsh wlan show networks mode=bssid" wide
  19. $b9="\\Lists\\BSSID.txt" wide
  20. $b10="\\Lists\\Discord\\Cookies" wide
  21. $b11="\\Lists\\FileZilla\\recentservers.xml" wide
  22. $b12="\\Lists\\ScreenCam.bmp" wide
  23. $b13="Error at hooking API \"%S\"" wide
  24. $b14="Dumping first %d bytes:" wide
  25. condition:
  26. 3 of ($a*) and 7 of ($b*)
  27. }
Add Comment
Please, Sign In to add comment