rule Windows_Trojan_Emmenhtalv2 : malware {
meta:
description = "Emmenhtal new version, data stage"
researcher = "Alexandre MATOUSEK"
source = "OCD"
creation_date = "18/12/2024"
os = "Windows"
category = "Trojan"
threat_name = "Windows.Trojan.Emmenhtal"
strings:
$ = ""
$ = ""
$ = " = document.documentElement.outerHTML;"
$ = ""
$ = ""
condition:
all of them
}