Files
roadwy-DefenderYara/Exploit/Win32/ShellCode/Exploit_Win32_Shellcode_MM_MTB.yar
2025-04-26 22:42:45 +08:00

11 lines
323 B
Plaintext

rule Exploit_Win32_Shellcode_MM_MTB{
meta:
description = "Exploit:Win32/Shellcode.MM!MTB,SIGNATURE_TYPE_PEHSTR,01 00 01 00 01 00 00 "
strings :
$a_01_0 = {33 c9 83 f8 29 0f 45 c8 8a 84 0c 80 00 00 00 30 84 14 b8 00 00 00 42 8d 41 01 81 fa 7d 08 00 00 72 de } //1
condition:
((#a_01_0 & 1)*1) >=1
}