mirror of
https://github.com/roadwy/DefenderYara
synced 2026-06-21 14:08:27 +00:00
15 lines
669 B
Plaintext
15 lines
669 B
Plaintext
|
|
rule Exploit_Linux_Looter_B_xp{
|
|
meta:
|
|
description = "Exploit:Linux/Looter.B!xp,SIGNATURE_TYPE_ELFHSTR_EXT,04 00 04 00 05 00 00 "
|
|
|
|
strings :
|
|
$a_01_0 = {73 75 63 6b 69 74 5f 73 65 6c 69 6e 75 78 } //2 suckit_selinux
|
|
$a_01_1 = {67 65 74 5f 65 78 70 6c 6f 69 74 5f 73 74 61 74 65 5f 70 74 72 } //2 get_exploit_state_ptr
|
|
$a_03_2 = {65 78 70 5f [0-15] 2e 63 } //2
|
|
$a_01_3 = {53 79 73 74 65 6d 20 69 73 20 6e 6f 74 20 76 75 6c 6e 65 72 61 62 6c 65 } //1 System is not vulnerable
|
|
$a_01_4 = {64 69 72 74 79 5f 63 6f 64 65 } //1 dirty_code
|
|
condition:
|
|
((#a_01_0 & 1)*2+(#a_01_1 & 1)*2+(#a_03_2 & 1)*2+(#a_01_3 & 1)*1+(#a_01_4 & 1)*1) >=4
|
|
|
|
} |