HKTL_NET_GUID_CVE_2020_1206_POC
Description
Detects .NET red/black-team tools via typelibguid
Query · yara
strings:
$typelibguid0lo = "3523ca04-a12d-4b40-8837-1a1d28ef96de" ascii wide
$typelibguid1lo = "d3a2f24a-ddc6-4548-9b3d-470e70dbcaab" ascii wide
$typelibguid2lo = "fb30ee05-4a35-45f7-9a0a-829aec7e47d9" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them