# CVE-2025-32433 YARA Detection Rule
**Author:** te0rwx
**Date:** 2025-08-27
## Description
This YARA rule is designed to detect:
- CVE-2025-32433 Erlang SSH remote code execution exploits.
- Reverse shells (Bash, nc, Erlang `os:cmd`) including obfuscated payloads (Base64, Hex, XOR, fragmented).
- Python, Go, and Bash scanners targeting Erlang SSH.
- Stealthy execution patterns, backgrounding, and sleep-delayed commands.
The rule **minimizes false positives** by requiring multiple exploit markers or multiple scanner indicators before matching.
---
## Usage
```bash
yara -r rule-cve-2025-32433.yar /path/to/scan
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view