Files
roadwy-DefenderYara/Exploit/Win32/ShellCode/Exploit_Win32_Shellcode_BS_MTB.yar
2025-04-26 22:42:45 +08:00

11 lines
359 B
Plaintext

rule Exploit_Win32_Shellcode_BS_MTB{
meta:
description = "Exploit:Win32/Shellcode.BS!MTB,SIGNATURE_TYPE_PEHSTR,01 00 01 00 01 00 00 "
strings :
$a_01_0 = {0f 45 d1 8d 4c 24 50 0f b6 44 14 50 30 84 34 8a 00 00 00 8d 44 24 51 03 c2 83 fa 0d 0f 45 c8 0f b6 01 b9 01 00 00 00 30 84 34 8b 00 00 00 } //1
condition:
((#a_01_0 & 1)*1) >=1
}