Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Note: an in-depth analysis of this tool will be posted shortly.
- ZXShell YARA rule:
- rule zxshell
- {
- meta:
- description = "ZXShell YARA rule"
- author = "Brian C. Bell - @biebsmalwareguy"
- strings:
- $s0 = "ZXHttpServer" nocase ascii
- $s1 = "ZXHttpProxy" nocase ascii
- $s2 = "ZXARPS" nocase ascii
- $s3 = "zxplug" nocase ascii
- condition:
- 2 of ($s*)
- }
Add Comment
Please, Sign In to add comment