Msfpayloads_msf_exe
Description
Metasploit Payloads - file msf-exe.vba
Query · yara
strings:
$s1 = "'* PAYLOAD DATA" fullword ascii
$s2 = " = Shell(" ascii
$s3 = "= Environ(\"USERPROFILE\")" fullword ascii
$s4 = "'**************************************************************" fullword ascii
$s5 = "ChDir (" ascii
$s6 = "'* MACRO CODE" fullword ascii
condition:
4 of them