CN_Honker_Injection
Description
Sample from CN Honker Pentest Toolset - file Injection.exe
Query · yara
strings: $s0 = "http://127.0.0.1/6kbbs/bank.asp" fullword ascii /* PEStudio Blacklist: strings */ $s7 = "jmPost.asp" fullword wide /* PEStudio Blacklist: strings */ condition: uint16(0) == 0x5a4d and filesize < 220KB and all of them