Windows_Ransomware_Royal_b7d42109
Description
Windows.Ransomware.Royal
Query · yara
strings:
$a1 = "Try Royal today and enter the new era of data security" ascii fullword
$a2 = "If you are reading this, it means that your system were hit by Royal ransomware." ascii fullword
$a3 = "http://royal"
$a4 = "\\README.TXT" wide fullword
condition:
all of them