MAL_Prolock_Malware
Description
Detects Prolock malware in encrypted and decrypted mode
Query · yara
strings:
$DecryptionRoutine = {01 C2 31 DB B8 ?? ?? ?? ?? 31 04 1A 81 3C 1A}
$DecryptedString1 = "support981723721@protonmail.com" nocase ascii
$DecryptedString2 = "Your files have been encrypted by ProLock Ransomware" nocase ascii
$DecryptedString3 = "msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion" nocase ascii
$CryptoCode = {B8 63 51 E1 B7 31 D2 8D BE ?? ?? ?? ?? B9 63 51 E1 B7 81 C1 B9 79 37 9E}
condition:
((uint16(0) == 0x5A4D) or (uint16(0) == 0x4D42)) and filesize < 100KB and (($DecryptionRoutine) or (1 of ($DecryptedString*) and $CryptoCode))