rule Windows_Trojan_Emmenhtalv2 : malware { meta: description = "Emmenhtal new version, data stage" researcher = "Alexandre MATOUSEK" source = "OCD" creation_date = "18/12/2024" os = "Windows" category = "Trojan" threat_name = "Windows.Trojan.Emmenhtal" strings: $ = "" $ = "" $ = " = document.documentElement.outerHTML;" $ = "" $ = "" condition: all of them }