Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule k_404_keylogger_bin
- {
- meta:
- description = "404k keylogger stealer"
- author = "James_inthe_box"
- reference = "dee0e0be670ab59a25129f2da51db6b7"
- date = "2019/01"
- maltype = "Keylogger"
- strings:
- $string1 = "opera_salt"
- $string2 = "set_loloa"
- $string3 = "PSWD | Client Name" wide
- $string4 = "api_paste_code" wide
- $string5 = "Lockdown2000" wide
- $string6 = "wow_logins" wide
- condition:
- uint16(0) == 0x5A4D and all of ($string*) and filesize < 300KB
- }
- rule k_404_keylogger_mem
- {
- meta:
- description = "404k keylogger stealer"
- author = "James_inthe_box"
- reference = "dee0e0be670ab59a25129f2da51db6b7"
- date = "2019/01"
- maltype = "Keylogger"
- strings:
- $string1 = "opera_salt"
- $string2 = "set_loloa"
- $string3 = "PSWD | Client Name" wide
- $string4 = "api_paste_code" wide
- $string5 = "Lockdown2000" wide
- $string6 = "wow_logins" wide
- condition:
- all of ($string*) and filesize > 300KB
- }
Add Comment
Please, Sign In to add comment