HKTL_NET_GUID_Povlsomware
Description
Detects c# red/black-team tools via typelibguid
Query · yara
strings:
$typelibguid0lo = "fe0d5aa7-538f-42f6-9ece-b141560f7781" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them