APT_UNC2447_MAL_RANSOM_HelloKitty_May21_2
Description
Detects HelloKitty Ransomware samples from UNC2447 campaign
Query · yara
strings:
$xop1 = { 50 8d 45 f8 50 ff 75 fc ff 15 ?? ?? 42 00 3d ea 00 00 00 75 18 83 7d f8 00 }
$s1 = "HelloKittyMutex" wide
$s2 = "%s\\read_me_lkd.txt" wide fullword
$s3 = "/C ping 127.0.0.1 & del %s" wide fullword
$s4 = "(%d) [%d] %s: STOP DOUBLE PROCESS RUN" ascii fullword
$sop1 = { 6a 00 6a 01 ff 75 fc ff 15 ?? ?? 42 00 85 c0 0f 94 c3 ff 75 fc ff 15 ?? ?? 42 00 }
$sop2 = { 74 12 6a 00 6a 01 ff 75 fc ff 15 ?? ?? 42 00 85 c0 0f 94 c3 ff 75 fc }
condition:
uint16(0) == 0x5a4d and
filesize < 600KB and
1 of ($x*) or 2 of them