Files
nuclei-templates/file/malware/cxpid-malware.yaml
2024-12-01 13:57:55 +00:00

27 lines
792 B
YAML

id: cxpid-malware
info:
name: Cxpid Malware - Detect
author: daffainfo
severity: info
reference: https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Cxpid.yar
tags: malware,file
file:
- extensions:
- all
matchers-condition: or
matchers:
- type: word
part: raw
words:
- '/cxpid/submit.php?SessionID='
- '/cxgid/'
- 'E21BC52BEA2FEF26D005CF'
- 'E21BC52BEA39E435C40CD8'
- ' -,L-,O+,Q-,R-,Y-,S-'
- type: binary
binary:
- "558BECB9380400006A006A004975F9"
# digest: 490a00463044022047a468bc7edf74b861ffeab5512f0cfecfcc423697ba4e4a7217dc4b169c984a02204d84fc62cee8fc71878087488f7639bb85f7d898c3bae5e260af88c3fa9f2cee:922c64590222798bb761d5b6d8e72950