(YARA) YARA_detect_tlscallback

Download Raw

rule detect_tlscallback {
    meta:
        description = "Simple rule to detect tls callback as anti-debug."
        author = "Thomas Roccia | @fr0gger_"
    strings:
        $str1 = "TLS_CALLBACK" nocase
        $str2 = "TLScallback" nocase
    condition:
        uint32(uint32(0x3C)) == 0x4550 and any of them
}

Associated Techniques

Technique Name Technique ID's Snippet(s) OS
TLS Callback U0124

Matching Samples 10 most recent

Sample Name Matching Techniques First Seen Last Seen
main.exe 11 2026-02-07 1 week ago
a.exe 7 2025-10-03 4 months, 1 week ago
program.exe 6 2025-10-01 4 months, 1 week ago
DSViper_AES.exe 8 2025-09-23 4 months, 3 weeks ago
xor.exe 6 2025-08-30 5 months, 2 weeks ago
hemlockwin.exe 8 2025-08-06 6 months, 1 week ago
teste.exe 6 2025-07-29 6 months, 2 weeks ago
libcrypto-1_1.dll 7 2025-07-01 7 months, 1 week ago
loader.exe 8 2025-05-29 8 months, 2 weeks ago
hello.exe 8 2024-12-27 1 year, 1 month ago
View All

Created

June 20, 2022

Last Revised

June 20, 2022