Commit 23aebeb8 by mmorenog Committed by GitHub

Create RANSOM_Comodosec.yar

parent 4dd667a3
This Yara ruleset is under the GNU-GPLv2 license ( and open to any user or organization, as long as you use it under this license.
rule ransom_comodosec_mrcr1 {
author = " J from THL <>"
date = "2017/01"
reference = ""
version = 1
maltype = "Ransomware"
filetype = "memory"
$text01 = "WebKitFormBoundary"
$text02 = "Start NetworkScan"
$text03 = "Start DriveScan"
$text04 = "Start CryptFiles"
$text05 = "cmd /c vssadmin delete shadows /all /quiet"
$text06 = "isAutorun:"
$text07 = "isNetworkScan:"
$text08 = "isUserDataLast:"
$text09 = "isCryptFileNames:"
$text10 = "isChangeFileExts:"
$text11 = "isPowerOffWindows:"
$text12 = "GatePath:"
$text13 = "GatePort:"
$text14 = "DefaultCryptKey:"
$text15 = "UserAgent:"
$text16 = "Mozilla_"
$text17 = "On Error Resume Next"
$text18 = "Content-Disposition: form-data; name=\"uid\""
$text19 = "Content-Disposition: form-data; name=\"uname\""
$text20 = "Content-Disposition: form-data; name=\"cname\""
$regx21 = /\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|\|[0-9a-z]{2,5}\|/
10 of them
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment