MAL_RANSOM_DarkBit_Feb23_1
Description
Detects indicators found in DarkBit ransomware
Query · yara
strings:
$s1 = ".onion" ascii
$s2 = "GetMOTWHostUrl"
$x1 = "hus31m7c7ad.onion"
$x2 = "iw6v2p3cruy"
$xn1 = "You will receive decrypting key after the payment."
condition:
uint16(0) == 0x5a4d and
filesize < 10MB and (
1 of ($x*) or 2 of them
) or 4 of them
or ( filesize < 10MB and $xn1 ) // Ransom note