Disclosed_0day_POCs_payload_MSI
Description
Detects POC code from disclosed 0day hacktool set
Query · yara
strings:
$s1 = "WShell32.dll" fullword wide
$s2 = "Target empty, so account name translation begins on the local system." fullword wide
$s3 = "\\custact\\x86\\AICustAct.pdb" ascii
condition:
(uint16(0) == 0xcfd0 and filesize < 1000KB and all of them)