MAL_RANSOM_Lorenz_May21_1
Description
Detects Lorenz Ransomware samples
Query · yara
strings:
$x1 = "process call create \"cmd.exe /c schtasks /Create /F /RU System /SC ONLOGON " ascii fullword
$x2 = "-----BEGIN PUBLIC KEY-----MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCn7fL/1qsWkJkUtXKZIJNqYfnVByVhK" ascii fullword
$s1 = "process call create \"cmd.exe /c schtasks /Create /F " ascii fullword
$s2 = "twr.ini" ascii fullword
$s3 = "/c wmic /node:'" ascii fullword
$op1 = { 0f 4f d9 81 ff dc 0f 00 00 5f 8d 4b 0? 0f 4e cb 83 fe 3c 5e 5b }
$op2 = { 6a 02 e8 ?? ?? 0? 00 83 c4 18 83 f8 01 75 01 cc 6a 00 68 ?? ?? 00 00 }
condition:
uint16(0) == 0x5a4d and
filesize < 4000KB and (
1 of ($x*) or
all of ($op*)
or 3 of them
)