ReversingLabs unknown stable yara
ByteCode_MSIL_Ransomware_Fantom [ransomware]
Yara rule that detects Fantom ransomware.
Detection Logic
uint16(0) == 0x5A4D and
(
(all of ($encrypt_files_*)) and
$lockfile and
$lockdir and
$sendkey
) Field Validations
Loading…
Comments (0)
Loading comments...