HKTL_NET_GUID_CVE_2020_1337
Description
Detects c# red/black-team tools via typelibguid
Query · yara
strings:
$typelibguid0lo = "d9c2e3c1-e9cc-42b0-a67c-b6e1a4f962cc" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them