Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)

Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.

FreeReviewedSigma · Critical · v5
Category
antivirus
Author
Florian Roth (Nextron Systems), Arnim Rupp (SigmaHQ), DRL 1.1
Published
2022-05-12
Updated
2026-07-31
title: Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
id: 7825641c-17c2-47ed-ba9f-9517bb897321
status: test
description: This rule flags Antivirus alerts whose signature name contains common ransomware family or indicator strings such as Babuk, Lockbit, Ryuk, and WannaCry. Even when the AV blocked the malware, these detections matter because they indicate a likely ransomware payload attempt occurred and should be investigated for initial access and execution context. Telemetry relies on Antivirus alert metadata, specifically the Signature field content matching the listed ransomware-related substrings.
references:
  - https://www.nextron-systems.com/?s=antivirus
  - https://www.virustotal.com/gui/file/43b0f7872900bd234975a0877744554f4f355dc57505517abd1ef611e1ce6916
  - https://www.virustotal.com/gui/file/c312c05ddbd227cbb08958876df2b69d0f7c1b09e5689eb9d93c5b357f63eff7
  - https://www.virustotal.com/gui/file/20179093c59bca3acc6ce9a4281e8462f577ffd29fd7bf51cf2a70d106062045
  - https://www.virustotal.com/gui/file/554db97ea82f17eba516e6a6fdb9dc04b1d25580a1eb8cb755eeb260ad0bd61d
  - https://www.virustotal.com/gui/file/69fe77dd558e281621418980040e2af89a2547d377d0f2875502005ce22bc95c
  - https://www.virustotal.com/gui/file/6f0f20da34396166df352bf301b3c59ef42b0bc67f52af3d541b0161c47ede05
  - https://github.com/SigmaHQ/sigma/blob/master/rules/category/antivirus/av_ransomware.yml
author: Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team
date: 2022-05-12
modified: 2026-06-15
tags:
  - attack.t1486
  - attack.impact
logsource:
  category: antivirus
detection:
  selection:
    Signature|contains:
      - Babuk
      - Babyk
      - BlackWorm
      - Chaos
      - Cobra
      - ContiCrypt
      - Crypter
      - Cryptes
      - Cryptor
      - CylanCrypt
      - DelShad
      - Destructor
      - Filecoder
      - GandCrab
      - GrandCrab
      - Haperlock
      - Hiddentear
      - HydraCrypt
      - Krypt
      - Lockbit
      - Locker
      - Mallox
      - Medusa
      - Phobos
      - Ransom
      - Rook
      - Ryuk
      - Ryzerlo
      - Stopcrypt
      - Tescrypt
      - TeslaCrypt
      - WannaCry
      - Xorist
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 4c6ca276-d4d0-4a8c-9e4c-d69832f8671f
    type: derived