Windows_Ransomware_Ryuk_88daaf8e
Description
Identifies RYUK ransomware
Query · yara
strings:
$f1 = { 48 8B CF E8 AB 25 00 00 85 C0 74 35 }
condition:
1 of ($f*)
Identifies RYUK ransomware
strings:
$f1 = { 48 8B CF E8 AB 25 00 00 85 C0 74 35 }
condition:
1 of ($f*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.