rule Exploit_Win32_Shellcode_SV_MTB{ meta: description = "Exploit:Win32/Shellcode.SV!MTB,SIGNATURE_TYPE_PEHSTR_EXT,04 00 04 00 04 00 00 " strings : $a_01_0 = {45 78 65 63 2d 53 68 65 6c 6c 63 6f 64 65 5c 78 36 34 5c 52 65 6c 65 61 73 65 5c 45 78 65 63 2d 53 68 65 6c 6c 63 6f 64 65 2e 70 64 62 } //1 Exec-Shellcode\x64\Release\Exec-Shellcode.pdb $a_01_1 = {49 6e 6a 65 63 74 69 6e 67 20 53 68 65 6c 6c 63 6f 64 65 20 54 68 65 20 4c 6f 63 61 6c 20 50 72 6f 63 65 73 73 } //1 Injecting Shellcode The Local Process $a_01_2 = {44 65 6f 62 66 75 73 63 61 74 65 64 20 50 61 79 6c 6f 61 64 } //1 Deobfuscated Payload $a_01_3 = {50 72 65 73 73 20 3c 45 6e 74 65 72 3e 20 54 6f 20 57 72 69 74 65 20 50 61 79 6c 6f 61 64 } //1 Press To Write Payload condition: ((#a_01_0 & 1)*1+(#a_01_1 & 1)*1+(#a_01_2 & 1)*1+(#a_01_3 & 1)*1) >=4 }