MAL_CRIME_RANSOM_DearCry_Mar21_1
Description
Detects DearCry Ransomware affecting Exchange servers
Query · yara
strings:
$s1 = "dear!!!" ascii fullword
$s2 = "EncryptFile.exe.pdb" ascii fullword
$s3 = "/readme.txt" ascii fullword
$s4 = "C:\\Users\\john\\" ascii
$s5 = "And please send me the following hash!" ascii fullword
$op1 = { 68 e0 30 52 00 6a 41 68 a5 00 00 00 6a 22 e8 81 d0 f8 ff 83 c4 14 33 c0 5e }
$op2 = { 68 78 6a 50 00 6a 65 6a 74 6a 10 e8 d9 20 fd ff 83 c4 14 33 c0 5e }
$op3 = { 31 40 00 13 31 40 00 a4 31 40 00 41 32 40 00 5f 33 40 00 e5 }
condition:
uint16(0) == 0x5a4d and
filesize < 4000KB and
3 of them or 5 of them