Windows_Ransomware_Ryuk_1a4ad952
Description
Identifies RYUK ransomware
Query · yara
strings:
$e1 = { 8B 0A 41 8D 45 01 45 03 C1 48 8D 52 08 41 3B C9 41 0F 45 C5 44 8B E8 49 63 C0 48 3B C3 72 E1 }
condition:
1 of ($e*)
Identifies RYUK ransomware
strings:
$e1 = { 8B 0A 41 8D 45 01 45 03 C1 48 8D 52 08 41 3B C9 41 0F 45 C5 44 8B E8 49 63 C0 48 3B C3 72 E1 }
condition:
1 of ($e*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.