Linux_Ransomware_RedAlert_39642d52
Description
Linux.Ransomware.RedAlert
Query · yara
strings:
$str_ransomnote = "\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\% REDALERT UNIQUE IDENTIFIER START \\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%\\%" ascii fullword
$str_print = "\t\t\t########\n\t\t\t[ N13V ]\n\t\t\t########\n\n" ascii fullword
$str_arg = "[info] Catch -t argument. Check encryption time" ascii fullword
$str_ext = ".crypt658" ascii fullword
$byte_checkvm = { 48 8B 14 DD ?? ?? ?? ?? 31 C0 48 83 C9 FF FC 48 89 EE 48 89 D7 F2 AE 4C 89 E7 48 F7 D1 E8 }
condition:
3 of ($str_*) or ($byte_checkvm and $str_print)