Files
roadwy-DefenderYara/Exploit/Win32/ShellCode/Exploit_Win32_ShellCode_AC.yar
T
2024-07-07 14:13:08 +08:00

11 lines
293 B
Plaintext

rule Exploit_Win32_ShellCode_AC{
meta:
description = "Exploit:Win32/ShellCode.AC,SIGNATURE_TYPE_PEHSTR_EXT,64 00 64 00 01 00 00 "
strings :
$a_01_0 = {81 7c 18 fc 4c 6f 77 5c 74 02 75 09 c6 86 99 00 00 00 01 eb 07 c6 86 99 00 00 00 00 } //1
condition:
((#a_01_0 & 1)*1) >=100
}