Windows_Ransomware_NightSpire_7b19fa09
Description
Windows.Ransomware.NightSpire
Query · yara
strings:
$a = "by NightSpire.Team" fullword
$b = ">>> Using qTox Chat App" fullword
$c = "/[NSPIRE_MSG].txt"
$d = "Answer.nspire"
$e = "change the icon of nspire file" fullword
$f = "main.MakeReadMeFile" fullword
$g = "main.writeToTail" fullword
$h = "main.checkPossibility" fullword
$i = "nightspireteam" fullword
$j = "Specify the Encryption Method."
condition:
4 of them