ReversingLabs unknown stable yara

ByteCode_MSIL_Ransomware_Fantom [ransomware]

Yara rule that detects Fantom ransomware.

View Source

Detection Logic

uint16(0) == 0x5A4D and
        (
            (all of ($encrypt_files_*)) and
            $lockfile and
            $lockdir and
            $sendkey
        )

Field Validations

Loading…

Comments (0)

Loading comments...