Advertisement
Guest User

MSEXCELOB_KINDALOOSE

a guest
Mar 22nd, 2018
478
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.42 KB | None | 0 0
  1. rule MSEXCELOB_KINDALOOSE {
  2. meta:
  3. version=".2"
  4. filetype="csv'ish"
  5. author="Ian.Ahl@TekDefense.com @TekDefense"
  6. date="2017-03-22"
  7. hashes="996f296283c594f233cdc6ad208b273d"
  8. strings:
  9.  
  10. // command
  11. $com1 = "=MSEXCEL|'\\.." ascii wide
  12. $com2 = "\"ms at fo\"" ascii wide
  13. $com3 = "do call %ihta" ascii wide
  14. $com4 = "http" ascii wide
  15.  
  16. condition:
  17. ( uint16(0) != 0x5a4d)
  18. and
  19. (2 of them)
  20. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement