Multi_Ransomware_BlackCat_00e525d7
Description
Multi.Ransomware.BlackCat
Query · yara
strings:
$a1 = "ata\",\"boot\",\"config.msi\",\"google\",\"perflogs\",\"appdata\",\"windows.old\"],\"exclude_file_names\":[\"desktop.ini\",\"aut"
$a2 = "locker::core::windows::processvssadmin.exe delete shadows /all /quietshadow_copy::remove_all=" ascii fullword
$a3 = "\\\\.\\pipe\\__rust_anonymous_pipe1__." ascii fullword
$a4 = "--bypass-p-p--bypass-path-path --no-prop-servers \\\\" ascii fullword
condition:
all of them