Windows_Ransomware_Vgod_86a877fd
Description
Windows.Ransomware.Vgod
Query · yara
strings:
$a1 = "Vgod-Ransomware/configuration.init" fullword
$a2 = "Vgod-Ransomware/encryption.EncryptFile" fullword
$a3 = "/Vgod-Ransomware/Vgod-Ransomware/Encryptor/encryption/encryption.go" fullword
$a4 = "main.removeBuiltExe" fullword
$a5 = "Contact Mail: vgod@ro.ru" fullword
$a6 = "Vgod-Built.exe" fullword
$a7 = "indicate your ID and if you want attach 2-3 infected files to generate a private key and compile the decryptor" fullword
$a8 = "--------- Attention ---------\nDo not rename encrypted files." fullword
condition:
3 of them