Windows_Ransomware_Inc_8f212220
Description
Windows.Ransomware.Inc
Query · yara
strings:
$a = "Couldn't delete shadow copies from" ascii wide fullword
$b = "Count of printers: %d\n" ascii wide fullword
$c = "Success! Closing printer: %s\n" ascii wide fullword
$d = "Encrypting file: %s\n" ascii wide fullword
$e = "Found drive: %s\n" ascii wide fullword
$f = "Loading hidden drives...\n" ascii wide fullword
$g = "--file <FILE>" ascii wide fullword
$h = "--safe-mode" ascii wide fullword
$i = "Starting full encryption in 5s" ascii wide fullword
condition:
4 of them