shadowbrokers-exploits/windows/Resources/Ep/Scripts/malfind/findsig36.eps
2017-04-14 11:45:07 +02:00

26 lines
528 B
PostScript

@include "PerlFunctions.epm";
string $logdir = GetEnv("_LPDIR_LOGS");
$logdir = "$logdir\\Logs";
@record on;
`local grep -path "$logdir" -mask "*processinfo*" -pattern kernel32.dll.aslr.`;
@record off;
string $filenames = GetCmdData('file_name');
if (sizeof($filenames) > 0)
{
return true;
}
@record on;
`local grep -path "$logdir" -mask "*processinfo*" -pattern "sort*.nls"`;
@record off;
string $filenames = GetCmdData('file_name');
if (sizeof($filenames) > 0)
{
return true;
}
return false;