MAL_RANSOM_LockBit_ForensicArtifacts_Apr23_1
Description
Detects forensic artifacts found in LockBit intrusions
Query · yara
strings:
$x1 = "/tmp/locker.log" ascii fullword
$x2 = "Executable=LockBit/locker_" ascii
/* Tor Browser Links:\x0d\x0ahttp://lockbit */
$xc1 = { 54 6F 72 20 42 72 6F 77 73 65 72 20 4C 69 6E 6B 73 3A 0D 0A 68 74 74 70 3A 2F 2F 6C 6F 63 6B 62 69 74 }
condition:
1 of ($x*)