Advertisement
Snakelabs

YaraRule: Win32Toxic : tox ransomware

Jun 1st, 2015
907
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. {
  2. meta:
  3. author = "@GelosSnake"
  4. date = "2015-06-02"
  5. description = "https://blogs.mcafee.com/mcafee-labs/meet-tox-ransomware-for-the-rest-of-us"
  6. hash0 = "70624c13be4d8a4c1361be38b49cb3eb"
  7. hash1 = "4f20d25cd3ae2e5c63d451d095d97046"
  8. hash2 = "e0473434cc83b57c4b579d585d4c4c57"
  9. hash3 = "c52090d184b63e5cc71b524153bb079e"
  10. hash4 = "7ac0b49baba9914b234cde62058c96a5"
  11. hash5 = "048c007de4902b6f4731fde45fa8e6a9"
  12. hash6 = "238ef3e35b14e304c87b9c62f18953a9"
  13. hash7 = "8908ccd681f66429c578a889e6e708e1"
  14. hash8 = "de9fe2b7d9463982cc77c78ee51e4d51"
  15. hash9 = "37add8d26a35a3dc9700b92b67625fa4"
  16. hash10 = "a0f30e89a3431fca1d389f90dba1d56e"
  17. sample_filetype = "exe"
  18. strings:
  19. $string0 = "n:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t:;;t;<<t;<<t;<<t;<<t;<<t;<<t;<<t;<<t<<<t;<<t;<<t;<<"
  20. $string1 = "t;<<t;<<t<<<t<<"
  21. $string2 = ">>><<<"
  22. condition:
  23. 2 of them
  24. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement