DefenderYara/Exploit/WinNT/CVE-2012-4681/Exploit_WinNT_CVE-2012-4681...

21 lines
1.5 KiB
Plaintext

rule Exploit_WinNT_CVE-2012-4681_AIO{
meta:
description = "Exploit:WinNT/CVE-2012-4681.AIO,SIGNATURE_TYPE_JAVAHSTR_EXT,0b 00 0b 00 0b 00 00 "
strings :
$a_01_0 = {01 00 25 28 4c 6a 61 76 61 2f 6c 61 6e 67 2f 53 74 72 69 6e 67 3b 29 4c 6a 61 76 61 2f 6c 61 6e 67 2f 43 6c 61 73 73 3b } //1
$a_01_1 = {01 00 3a 28 4c 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 3b 4c 6a 61 76 61 2f 6c 61 6e 67 2f 53 74 72 69 6e 67 3b 5b 4c 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 3b 29 56 } //1
$a_01_2 = {01 00 12 73 75 6e 2e 61 77 74 2e 53 75 6e 54 6f 6f 6c 6b 69 74 } //1
$a_01_3 = {01 00 15 6a 61 76 61 2f 62 65 61 6e 73 2f 45 78 70 72 65 73 73 69 6f 6e } //1
$a_01_4 = {01 00 14 28 29 4c 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 3b } //1
$a_01_5 = {01 00 17 6a 61 76 61 2f 6c 61 6e 67 2f 72 65 66 6c 65 63 74 2f 46 69 65 6c 64 } //1
$a_01_6 = {01 00 07 65 78 65 63 75 74 65 } //1
$a_01_7 = {01 00 10 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 } //1
$a_01_8 = {01 00 08 67 65 74 56 61 6c 75 65 } //1
$a_01_9 = {01 00 27 28 4c 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 3b 4c 6a 61 76 61 2f 6c 61 6e 67 2f 4f 62 6a 65 63 74 3b 29 56 } //1
$a_01_10 = {05 bd 3a 19 03 2b 53 19 04 2c 53 bb 59 2a 12 b7 12 19 b7 3a 19 b6 19 b6 c0 2d 19 b6 b1 } //1
condition:
((#a_01_0 & 1)*1+(#a_01_1 & 1)*1+(#a_01_2 & 1)*1+(#a_01_3 & 1)*1+(#a_01_4 & 1)*1+(#a_01_5 & 1)*1+(#a_01_6 & 1)*1+(#a_01_7 & 1)*1+(#a_01_8 & 1)*1+(#a_01_9 & 1)*1+(#a_01_10 & 1)*1) >=11
}