Windows_Ransomware_Phobos_11ea7be5
Description
Identifies Phobos ransomware
Query · yara
strings:
$b1 = { C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89 }
condition:
1 of ($b*)
Identifies Phobos ransomware
strings:
$b1 = { C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89 }
condition:
1 of ($b*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.