HKTL_NET_GUID_CVE_2019_1253
Description
Detects c# red/black-team tools via typelibguid
Query · yara
strings:
$typelibguid0lo = "584964c1-f983-498d-8370-23e27fdd0399" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them