BKDR_XZUtil_Script_CVE_2024_3094_Mar24_1
Description
Detects make file and script contents used by the backdoored XZ library (xzutil) CVE-2024-3094.
Query · yara
strings:
$x1 = "/bad-3-corrupt_lzma2.xz | tr " ascii
$x2 = "/tests/files/good-large_compressed.lzma|eval $i|tail -c +31265|" ascii
$x3 = "eval $zrKcKQ" ascii
condition:
1 of them