MAL_EXE_RoyalRansomware
Description
Detection for Royal Ransomware seen Dec 2022
Query · yara
strings:
$x_ext = ".royal_" wide
$x_fname = "royal_dll.dll"
$s_readme = "README.TXT" wide
$s_cli_flag01 = "-networkonly" wide
$s_cli_flag02 = "-localonly" wide
$x_ransom_msg01 = "If you are reading this, it means that your system were hit by Royal ransomware."
$x_ransom_msg02 = "Try Royal today and enter the new era of data security!"
$x_onion_site = "http://royal2xthig3ou5hd7zsliqagy6yygk2cdelaxtni2fyad6dpmpxedid.onion/"
condition:
uint16(0) == 0x5A4D and
(
2 of ($x*) or
5 of them
)