Add yara/volt_typhoon_cisa.md
This commit is contained in:
15
yara/volt_typhoon_cisa.md
Normal file
15
yara/volt_typhoon_cisa.md
Normal file
@ -0,0 +1,15 @@
|
||||
|
||||
|
||||
```
|
||||
rule ShellJSP {
|
||||
strings:
|
||||
$s1 = "decrypt(fpath)"
|
||||
$s2 = "decrypt(fcontext)"
|
||||
$s3 = "decrypt(commandEnc)"
|
||||
$s4 = "upload failed!"
|
||||
$s5 = "aes.encrypt(allStr)"
|
||||
$s6 = "newid"
|
||||
condition:
|
||||
filesize < 50KB and 4 of them
|
||||
}
|
||||
```
|
Reference in New Issue
Block a user