This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as long as you use it under this license.
*/
rule Meterpreter_Reverse_Tcp {
meta: // This is the standard backdoor/RAT from Metasploit, could be used by any actor
author = "chort (@chort0)"
description = "Meterpreter reverse TCP backdoor in memory. Tested on Win7x64."