MAL_Ransomware_GermanWiper
Description
Detects RansomWare GermanWiper in Memory or in unpacked state
Query · yara
strings:
$x_Mutex1 = "HSDFSD-HFSD-3241-91E7-ASDGSDGHH" ascii
$x_Mutex2 = "cFgxTERNWEVhM2V" ascii
// code patterns for process kills
$PurgeCode = { 6a 00 8b 47 08 50 6a 00 6a 01 e8 ?? ?? ?? ??
50 e8 ?? ?? ?? ?? 8b f0 8b d7 8b c3 e8 }
$ProcessKill1 = "sqbcoreservice.exe" ascii
$ProcessKill2 = "isqlplussvc.exe" ascii
$KillShadowCopies = "vssadmin.exe delete shadows" ascii
$Domain1 = "cdnjs.cloudflare.com" ascii
$Domain2 = "expandingdelegation.top" ascii
$RansomNote = "Entschluesselungs_Anleitung.html" ascii
condition:
uint16(0) == 0x5A4D and filesize < 1000KB and
( 1 of ($x*) or 3 of them )