Windows_Ransomware_Rook_ee21fa67
Description
Windows.Ransomware.Rook
Query · yara
strings:
$a = { 01 75 09 8B C3 FF C3 48 89 74 C5 F0 48 FF C7 48 83 FF 1A 7C DB }
condition:
all of them
Windows.Ransomware.Rook
strings:
$a = { 01 75 09 8B C3 FF C3 48 89 74 C5 F0 48 FF C7 48 83 FF 1A 7C DB }
condition:
all of them
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.