HKTL_NET_GUID_CVE_2019_1064
Description
Detects c# red/black-team tools via typelibguid
Query · yara
strings:
$typelibguid0lo = "ff97e98a-635e-4ea9-b2d0-1a13f6bdbc38" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them