Yara Rule for CVE-2010-1297

Posted: June 11th, 2010 | Author: | Filed under: IT Related | Tags: , , , , , | 1 Comment »
rule FlashNewfunction: decodedPDF
      ref = "CVE-2010-1297"
      hide = true
      impact = 5 
      $unescape = "unescape" fullword nocase
      $shellcode = /%u[A-Fa-f0-9]{4}/
      $shellcode5 = /(%u[A-Fa-f0-9]{4}){5}/
      $cve20101297 = /\/Subtype ?\/Flash/
      ($unescape and $shellcode and $cve20101297) or ($shellcode5 and $cve20101297)

One Comment on “Yara Rule for CVE-2010-1297”

  1. 1 Tweets that mention Yara Rule for CVE-2010-1297 | Xanda's Blog !~! -- Topsy.com said at 7:04 PM on June 11th, 2010:

    […] This post was mentioned on Twitter by Gadix, Mila and Fakhri Me, xanda. xanda said: Yara Rule for CVE-2010-1297 http://goo.gl/sPFg […]

Leave a Reply