Skip to content

Commit

Permalink
Add relay.dll and vmtools.dll (#79)
Browse files Browse the repository at this point in the history
  • Loading branch information
JPMinty authored May 31, 2024
1 parent 9ec9e56 commit b576fac
Show file tree
Hide file tree
Showing 3 changed files with 63 additions and 0 deletions.
20 changes: 20 additions & 0 deletions yml/3rd_party/canon/relay.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
Name: relay.dll
Author: Jai Minton - HuntressLabs
Created: 2024-05-27
Vendor: Canon
VulnerableExecutables:
- Path: 'UniversalInstaller.exe'
Type: Sideloading
ExpectedVersionInformation:
- OriginalFilename: UniversalInstaller.exe
InternalName: UniversalInstaller.exe
FileDescription: Universal Installer Windows
SHA256:
- a05b592a971fe5011554013bcfe9a4aaf9cfc633bdd1fe3a8197f213d557b8d3
Resources:
- https://www.virustotal.com/gui/file/6122b4ceb394e4a441b4f7ac92745b1aa64b6c83a4101d6d326e130efa5a5d10/details
Acknowledgements:
- Name: Jai Minton
Company: Huntress
Twitter: '@cyberrraiju'
24 changes: 24 additions & 0 deletions yml/3rd_party/vmware/vmtools.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
---
Name: vmtools.dll
Author: Jai Minton - HuntressLabs
Created: 2024-05-27
Vendor: VMWare
ExpectedLocations:
- '%PROGRAMFILES%\VMware\VMware Tools'
- '%PROGRAMFILES%\VMware\VMware Workstation'
- '%PROGRAMFILES%\VMware\VMware Player'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\VMware\VMware Tools\rvmSetup.exe'
Type: Sideloading
ExpectedVersionInformation:
- OriginalFilename: rvmSetup.exe
InternalName: rvmSetup
FileDescription: VMware RVM Setup Service
SHA256:
- 0e6f5eaa2cd91747213f6aec05e3de6fb46ea2b7cf4d5f3ac267128abc784d00
Resources:
- https://www.virustotal.com/gui/file/a3d340480fc015cd7c548fccad9218222c37178af95727b612d768d8e4b24964/details
Acknowledgements:
- Name: Jai Minton
Company: Huntress
Twitter: '@cyberrraiju'
19 changes: 19 additions & 0 deletions yml/microsoft/external/msidcrl40.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
Name: msidcrl40.dll
Author: Jai Minton - HuntressLabs
Created: 2024-05-29
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\msn messenger'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\msn messenger\livecall.exe'
Type: Sideloading
SHA256:
- '63ec17feda1f0ea80e0dd7b7938fbf7354aedf8d9f4041543afca9a35337f7bf'
Resources:
- https://www.virustotal.com/gui/file/e2787ddbbf2a7304827a17d698f7cede17edbf0633d36f39f4c020ee8f37ccd1
- https://www.virustotal.com/gui/file/448bfca5913e45ec36863ec2e72d959bd1f8ac30e0c794b708b3a6f45a050ef4
Acknowledgements:
- Name: Jai Minton
Company: Huntress
Twitter: '@cyberrraiju'

0 comments on commit b576fac

Please sign in to comment.