Windows_Ransomware_Helloxd_0c50f01b
Description
Windows.Ransomware.Helloxd
Query · yara
strings:
$mutex = "With best wishes And good intentions..."
$ransomnote0 = ":: our TOX below >:)"
$ransomnote1 = "You can download TOX here"
$ransomnote2 = "...!XD ::"
$productname = "HelloXD" ascii wide
$legalcopyright = "uKn0w" ascii wide
$description = "VhlamAV" ascii wide
$companyname = "MicloZ0ft" ascii wide
condition:
($mutex and all of ($ransomnote*)) or (3 of ($productname, $legalcopyright, $description, $companyname))