Windows_Ransomware_Nefilim_3969d6a7
Description
Windows.Ransomware.Nefilim
Query · yara
strings:
$a = "NEF1LIM"
$b = "-DECRYPT.txt"
$c = "main.BytesToPublicKey"
condition:
all of them
Windows.Ransomware.Nefilim
strings:
$a = "NEF1LIM"
$b = "-DECRYPT.txt"
$c = "main.BytesToPublicKey"
condition:
all of them
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.