MalwareBazaar Database

This page shows some basic information the YARA rule exploit_any_poppopret including corresponding malware samples.

Database Entry


YARA Rule:exploit_any_poppopret
Author:Jeff White [karttoon@gmail.com] @noottrak
Description:Identify POP -> POP -> RET opcodes for quick ROP Gadget creation in target binaries.
Firstseen:2022-06-14 11:26:51 UTC
Lastseen:2022-10-08 11:55:43 UTC
Sightings:2'327

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter