Windows_Ransomware_Phobos_ff55774d
Description
Identifies Phobos ransomware
Query · yara
strings:
$c1 = { 24 18 83 C4 0C 8B 4F 0C 03 C6 50 8D 54 24 18 52 51 6A 00 6A 00 89 44 }
condition:
1 of ($c*)
Identifies Phobos ransomware
strings:
$c1 = { 24 18 83 C4 0C 8B 4F 0C 03 C6 50 8D 54 24 18 52 51 6A 00 6A 00 89 44 }
condition:
1 of ($c*)
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.