avg_antivirus__avast_antivirus_dll_search_order_hijacking_and_potential_abuses
Description
Detects CVE-2019-17093 exploitation attempt License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
(($selection1.metadata.product_event_type = "7" and re.regex($selection1.target.process.file.full_path, `.*/AVGSvc\.exe`) and $selection1.target.process.file.full_path = "C:\\Windows\\System32\\wbem\\wbemcomn.dll") or ($selection1.metadata.product_event_type = "11" and ($selection1.target.file.full_path = "C:\\Program Files\\System32\\wbemcomn.dll" or $selection1.target.file.full_path = "C:\\Windows\\System32\\wbem\\wbemcomn.dll")))
condition:
$selection1