Commit 1a08b908 by Marc Rivero López

Create derkziel_stealer

parent ca34ae65
rule Derkziel
{
meta:
description = "Derkziel info stealer (Steam, Opera, Yandex, ...)"
author = "The Malware Hunter"
yaraexchange = "No distribution without author's consent"
filetype = "pe"
date = "2015-11"
md5 = "f5956953b7a4acab2e6fa478c0015972"
site = "https://zoo.mlw.re/samples/f5956953b7a4acab2e6fa478c0015972"
reference = "https://bhf.su/threads/137898/"
strings:
$drz = "{!}DRZ{!}"
$ua = "User-Agent: Uploador"
$steam = "SteamAppData.vdf"
$login = "loginusers.vdf"
$config = "config.vdf"
condition:
all of them
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment