Add yara/volt_typhoon_cisa.md
This commit is contained in:
15
yara/volt_typhoon_cisa.md
Normal file
15
yara/volt_typhoon_cisa.md
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
|
||||||
|
|
||||||
|
```
|
||||||
|
rule ShellJSP {
|
||||||
|
strings:
|
||||||
|
$s1 = "decrypt(fpath)"
|
||||||
|
$s2 = "decrypt(fcontext)"
|
||||||
|
$s3 = "decrypt(commandEnc)"
|
||||||
|
$s4 = "upload failed!"
|
||||||
|
$s5 = "aes.encrypt(allStr)"
|
||||||
|
$s6 = "newid"
|
||||||
|
condition:
|
||||||
|
filesize < 50KB and 4 of them
|
||||||
|
}
|
||||||
|
```
|
Reference in New Issue
Block a user