Windows_Ransomware_Ryuk_72b5fd9d
Description
Identifies RYUK ransomware
Query · yara
strings:
$d1 = { 48 2B C3 33 DB 66 89 1C 46 48 83 FF FF 0F }
condition:
1 of ($d*)
Identifies RYUK ransomware
strings:
$d1 = { 48 2B C3 33 DB 66 89 1C 46 48 83 FF FF 0F }
condition:
1 of ($d*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.