Invoke_Metasploit
Description
Detects Invoke-Metasploit Payload
Query · yara
strings:
$s1 = "[*] Looks like we're 64bit, using regular powershell.exe" ascii wide
$s2 = "[*] Kicking off download cradle in a new process"
$s3 = "Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;Invoke-Expression $client.downloadstring('''+$url+''');'"
condition:
(filesize < 20KB and 1 of them)