DefenderYara/Exploit/O97M/CVE-2017-11882/Exploit_O97M_CVE-2017-11882...

12 lines
667 B
Plaintext

rule Exploit_O97M_CVE-2017-11882_CE_MTB{
meta:
description = "Exploit:O97M/CVE-2017-11882.CE!MTB,SIGNATURE_TYPE_MACROHSTR_EXT,02 00 02 00 02 00 00 "
strings :
$a_03_0 = {53 75 62 20 41 75 74 6f 5f 4f 70 65 6e 28 29 90 0c 02 00 75 72 6a 6b 64 65 37 33 65 33 67 79 37 34 74 33 20 3d 20 75 72 6a 6b 64 65 37 33 65 33 67 79 37 34 74 33 20 2b 20 22 64 75 64 79 79 36 69 77 6e 62 20 3d 20 22 22 } //1
$a_03_1 = {2b 20 76 62 43 72 4c 66 20 27 68 36 37 32 34 33 36 72 75 69 32 90 0c 02 00 75 72 6a 6b 64 65 37 33 65 33 67 79 37 34 74 33 20 3d 20 75 72 6a 6b 64 65 37 33 65 33 67 79 37 34 74 33 20 2b } //1
condition:
((#a_03_0 & 1)*1+(#a_03_1 & 1)*1) >=2
}