Windows_Ransomware_Dharma_942142e3
Description
Identifies DHARMA ransomware
Query · yara
strings:
$a1 = "C:\\crysis\\Release\\PDB\\payload.pdb" ascii fullword
condition:
1 of ($a*)
Identifies DHARMA ransomware
strings:
$a1 = "C:\\crysis\\Release\\PDB\\payload.pdb" ascii fullword
condition:
1 of ($a*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.