Windows_Ransomware_Medusa_fda487fd
Description
Windows.Ransomware.Medusa
Query · yara
strings:
$a1 = "kill_processes %s" ascii fullword
$a2 = "kill_services %s" ascii fullword
$a3 = ":note path = %s" ascii fullword
$a4 = "Write Note file error:%s" ascii fullword
$a5 = "Rename file error:%s" ascii fullword
$a6 = "G:\\Medusa\\Release\\gaze.pdb" ascii fullword
condition:
5 of them