ReversingLabs unknown stable yara

Win32_Ransomware_Armage [ransomware]

Yara rule that detects Armage ransomware.

View Source

Detection Logic

uint16(0) == 0x5A4D and 
        (
            all of ($enum_resources_p*) 
        ) and 
        (
            all of ($find_files_p*)
        ) and 
        (
            all of ($encrypt_files_p*)
        )

Field Validations

Loading…

Comments (0)

Loading comments...