
Rule Info
Name
BCKDR_XZUtil_KillSwitch_CVE_2024_3094_Mar24_1
Author
Florian Roth
Description
Detects kill switch used by the backdoored XZ library (xzutil) CVE-2024-3094.
Score
85
Date
2024-03-30
Minimum Yara
1.7
Rule Hash
8abe4124921a5ec286f6174047532ff6
Tags
['DEMO', 'CVE_2024_3094']
Required Modules
[]
Virustotal Matches
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
6
Suspicious (< 10 engines)
3
Clean (0 engines)
3
Rule Matches
Timestamp
Positives
Total
Hash
VT