Windows_Trojan_Metasploit_4a1c4da8
Description
Identifies Metasploit 64 bit reverse tcp shellcode.
Query · yara
strings:
$a = { 6A 10 56 57 68 99 A5 74 61 FF D5 85 C0 74 0A FF 4E 08 }
condition:
all of them
Identifies Metasploit 64 bit reverse tcp shellcode.
strings:
$a = { 6A 10 56 57 68 99 A5 74 61 FF D5 85 C0 74 0A FF 4E 08 }
condition:
all of them
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.