Antivirus ransomware signature alert based on known family name strings
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
FreeUnreviewedSigmacriticalv1
antivirus-ransomware-signature-alert-based-on-known-family-name-strings-4c6ca276
title: Antivirus ransomware signature alert based on known family name strings
id: 7825641c-17c2-47ed-ba9f-9517bb897321
status: test
description: This rule matches antivirus alerts whose signature text contains multiple ransomware-family name strings (e.g., Ryuk, Lockbit, WannaCry, GandCrab, Babuk). Such detections matter because they indicate ransomware may have been present or attempted, even when the antivirus blocked the threat. The rule relies on antivirus telemetry that includes a Signature field containing those identifying substrings.
references:
- https://www.nextron-systems.com/?s=antivirus
- https://www.virustotal.com/gui/file/43b0f7872900bd234975a0877744554f4f355dc57505517abd1ef611e1ce6916
- https://www.virustotal.com/gui/file/c312c05ddbd227cbb08958876df2b69d0f7c1b09e5689eb9d93c5b357f63eff7
- https://www.virustotal.com/gui/file/20179093c59bca3acc6ce9a4281e8462f577ffd29fd7bf51cf2a70d106062045
- https://www.virustotal.com/gui/file/554db97ea82f17eba516e6a6fdb9dc04b1d25580a1eb8cb755eeb260ad0bd61d
- https://www.virustotal.com/gui/file/69fe77dd558e281621418980040e2af89a2547d377d0f2875502005ce22bc95c
- https://www.virustotal.com/gui/file/6f0f20da34396166df352bf301b3c59ef42b0bc67f52af3d541b0161c47ede05
- https://github.com/SigmaHQ/sigma/blob/master/rules/category/antivirus/av_ransomware.yml
author: Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team
date: 2022-05-12
modified: 2026-06-15
tags:
- attack.t1486
- attack.impact
logsource:
category: antivirus
detection:
selection:
Signature|contains:
- Babuk
- Babyk
- BlackWorm
- Chaos
- Cobra
- ContiCrypt
- Crypter
- Cryptes
- Cryptor
- CylanCrypt
- DelShad
- Destructor
- Filecoder
- GandCrab
- GrandCrab
- Haperlock
- Hiddentear
- HydraCrypt
- Krypt
- Lockbit
- Locker
- Mallox
- Medusa
- Phobos
- Ransom
- Rook
- Ryuk
- Ryzerlo
- Stopcrypt
- Tescrypt
- TeslaCrypt
- WannaCry
- Xorist
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 4c6ca276-d4d0-4a8c-9e4c-d69832f8671f
type: derived
What it detects
This rule matches antivirus alerts whose signature text contains multiple ransomware-family name strings (e.g., Ryuk, Lockbit, WannaCry, GandCrab, Babuk). Such detections matter because they indicate ransomware may have been present or attempted, even when the antivirus blocked the threat. The rule relies on antivirus telemetry that includes a Signature field containing those identifying substrings.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.