Windows_Ransomware_Ragnarok_efafbe48
Description
Identifies RAGNAROK ransomware
Query · yara
strings:
$a1 = "cmd_firewall" ascii fullword
$a2 = "cmd_recovery" ascii fullword
$a3 = "cmd_boot" ascii fullword
$a4 = "cmd_shadow" ascii fullword
$a5 = "readme_content" ascii fullword
$a6 = "readme_name" ascii fullword
$a8 = "rg_path" ascii fullword
$a9 = "cometosee" ascii fullword
$a10 = "&prv_ip=" ascii fullword
condition:
6 of ($a*)