nuclei-templates/file/malware/cxpid-malware.yaml

29 lines
798 B
YAML
Raw Permalink Normal View History

2023-08-01 11:37:58 +00:00
id: cxpid-malware
2023-02-28 01:18:13 +00:00
info:
2023-03-09 18:14:31 +00:00
name: Cxpid Malware - Detect
2023-02-28 01:18:13 +00:00
author: daffainfo
2023-08-01 09:54:35 +00:00
severity: info
2023-02-28 01:18:13 +00:00
reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Cxpid.yar
tags: malware,file
file:
- extensions:
- all
matchers-condition: or
matchers:
2023-08-01 09:54:35 +00:00
- type: word
part: raw
2023-02-28 01:18:13 +00:00
words:
- '/cxpid/submit.php?SessionID='
- '/cxgid/'
- 'E21BC52BEA2FEF26D005CF'
- 'E21BC52BEA39E435C40CD8'
- ' -,L-,O+,Q-,R-,Y-,S-'
2023-08-01 09:54:35 +00:00
- type: binary
2023-02-28 01:18:13 +00:00
binary:
2023-10-14 11:27:55 +00:00
- "558BECB9380400006A006A004975F9"
# digest: 4b0a00483046022100a74a127323c94ac22930026e66dd642dd77e020a5196c7595f654c18025ff3c3022100d1b6de3cb0908fd76b6556d63cd1a4b9208813f689c9e870cb1a83c55ba41970:922c64590222798bb761d5b6d8e72950