MAL_RANSOM_SH_ESXi_Attacks_Feb23_2
Description
Detects script used in ransomware attacks exploiting and encrypting ESXi servers
Query · yara
strings:
$x1 = "echo \"START ENCRYPT: $file_e SIZE: $size_kb STEP SIZE: " ascii
condition:
filesize < 10KB and 1 of them