Windows_Exploit_Generic_e95cc41c
Description
Windows.Exploit.Generic
Query · yara
strings:
$s1 = "Got system privileges" nocase
$s2 = "Got SYSTEM token" nocase
$s3 = "Got a SYSTEM token" nocase
$s4 = "] Duplicating SYSTEM token" nocase
$s5 = "] Token Stealing is successful" nocase
$s6 = "] Exploit completed" nocase
condition:
any of them