mirror of
https://github.com/roadwy/DefenderYara
synced 2026-06-21 14:08:27 +00:00
14 lines
868 B
Plaintext
14 lines
868 B
Plaintext
|
|
rule Exploit_Win32_Shellcode_SV_MTB{
|
|
meta:
|
|
description = "Exploit:Win32/Shellcode.SV!MTB,SIGNATURE_TYPE_PEHSTR_EXT,04 00 04 00 04 00 00 "
|
|
|
|
strings :
|
|
$a_01_0 = {45 78 65 63 2d 53 68 65 6c 6c 63 6f 64 65 5c 78 36 34 5c 52 65 6c 65 61 73 65 5c 45 78 65 63 2d 53 68 65 6c 6c 63 6f 64 65 2e 70 64 62 } //1 Exec-Shellcode\x64\Release\Exec-Shellcode.pdb
|
|
$a_01_1 = {49 6e 6a 65 63 74 69 6e 67 20 53 68 65 6c 6c 63 6f 64 65 20 54 68 65 20 4c 6f 63 61 6c 20 50 72 6f 63 65 73 73 } //1 Injecting Shellcode The Local Process
|
|
$a_01_2 = {44 65 6f 62 66 75 73 63 61 74 65 64 20 50 61 79 6c 6f 61 64 } //1 Deobfuscated Payload
|
|
$a_01_3 = {50 72 65 73 73 20 3c 45 6e 74 65 72 3e 20 54 6f 20 57 72 69 74 65 20 50 61 79 6c 6f 61 64 } //1 Press <Enter> To Write Payload
|
|
condition:
|
|
((#a_01_0 & 1)*1+(#a_01_1 & 1)*1+(#a_01_2 & 1)*1+(#a_01_3 & 1)*1) >=4
|
|
|
|
} |