Windows_Ransomware_Hellokitty_4b668121
Description
Windows.Ransomware.Hellokitty
Query · yara
strings:
$a1 = "(%d) [%d] %s: STOP DOUBLE PROCESS RUN" ascii fullword
$a2 = "(%d) [%d] %s: Looking for folder from cmd: %S" ascii fullword
$a3 = "(%d) [%d] %s: ERROR: Failed to encrypt AES block" ascii fullword
$a4 = "gHelloKittyMutex" wide fullword
$a5 = "/C ping 127.0.0.1 & del %s" wide fullword
$a6 = "Trying to decrypt or modify the files with programs other than our decryptor can lead to permanent loss of data!"
$a7 = "read_me_lkdtt.txt" wide fullword
$a8 = "If you want to get it, you must pay us some money and we will help you." wide fullword
condition:
5 of them