(YARA) YARA_ModifyDLLExportName
rule ModifyDLLExportName {
strings:
$map_and_load = "MapAndLoad"
$entry_to_data = "ImageDirectoryEntryToData"
$rva_to_va = "ImageRvaToVa"
$modify = "ModifyDLLExportName"
$virtual_protect = "VirtualProtect"
$virtual_alloc = "VirtualAlloc"
condition:
all of them
}
Associated Techniques
Technique Name | Technique ID's | Snippet(s) | OS |
---|---|---|---|
Tamper DLL Export Names & GetProcAddress Spoofing | U1241 |
Created
December 6, 2022
Last Revised
December 6, 2022