HKTL_NET_GUID_p2p
Description
Detects .NET red/black-team tools via typelibguid (p2p Remote Desktop is dual use but 100% flagged as malicious on VT)
Query · yara
strings:
$typelibguid0lo = "33456e72-f8e8-4384-88c4-700867df12e2" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them