Disclosed_0day_POCs_lpe_2
Description
Detects POC code from disclosed 0day hacktool set
Query · yara
strings:
$s1 = "\\cmd.exe\" /k wusa c:\\users\\" ascii
$s2 = "D:\\gitpoc\\UAC\\src\\x64\\Release\\lpe.pdb" fullword ascii
$s3 = "Folder Created: " fullword wide
condition:
(uint16(0) == 0x5a4d and filesize < 700KB and 2 of them)