SYMBOLCOMMON_NAMEaka. SYNONYMS
win.blackbasta (Back to overview)

Black Basta

aka: no_name_software

Actor(s): GOLD REBELLION, STAC5143, Storm-0506, Storm-0826, TA2101, UNC3973, UNC4393

VTCollection    

"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.

References
2026-05-18 ⋅ Zynap ⋅ Oscar Gallego
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis
Black Basta HijackLoader
2026-01-15 ⋅ ANALYST1 ⋅ Anastasia Sentsova
Infrastructure in the Shadows: How Two Leaks Unmasked the Criminal Network of Yalishanda aka Media Land, and BlackBasta
Black Basta Black Basta
2025-04-24 ⋅ Mandiant ⋅ Mandiant
M-Trends 2025 Report
Akira Black Basta LockBit SystemBC GootLoader LockBit WIREFIRE Akira Black Basta Cobalt Strike LockBit RansomHub SystemBC Pink Sandstorm
2025-04-16 ⋅ SpyCloud ⋅ Aurora Johnson, Keegan Keplinger
Exposed Credentials & Ransomware Operations: Using LLMs to Digest 200K Messages from the Black Basta Chats
Black Basta Black Basta
2025-04-15 ⋅ ⋅ Orange Cyberdefense ⋅ André Henschel, Friedl Holzner
CyberSOC Insights: Analysis of a Black Basta Attack Campaign
Black Basta DarkGate Lumma Stealer
2025-04-08 ⋅ Trustwave ⋅ Nikita Kazymirskyi, Serhii Melnyk
A deep Dive into the Leaked Black Basta Chat Logs
Black Basta Black Basta
2025-04-02 ⋅ ANALYST1 ⋅ analyst1
Inside BlackBasta: Actor Profiles, Extortion Tactics & Finances
Black Basta Black Basta
2025-04-02 ⋅ Intel 471 ⋅ Intel 471
An in-depth look at Black Basta's TTPs
Black Basta Black Basta
2025-03-18 ⋅ Expel ⋅ AARON WALTON
Code-signing certificate abuse in the Black Basta chat leaks (and how to fight back)
Black Basta Black Basta
2025-03-18 ⋅ Trellix ⋅ Jambul Tologonov, John Fokker
Analysis of Black Basta Ransomware Chat Leaks
Black Basta Black Basta
2025-03-17 ⋅ Cloudflare ⋅ Cloudflare
Black Basta’s blunder: exploiting the gang’s leaked chats
Black Basta Black Basta
2025-03-13 ⋅ EclecticIQ ⋅ Arda Büyükkaya
Inside BRUTED: Black Basta (RaaS) Members Used Automated Brute Forcing Framework to Target Edge Network Devices
Black Basta
2025-03-12 ⋅ Youtube (AhmedS Kasmani) ⋅ AhmedS Kasmani
Initial Analysis of Black Basta Chat Leaks
Black Basta Black Basta
2025-03-12 ⋅ YouTube (John Hammond) ⋅ John Hammond
LEAKED Russian Hackers Internal Chats
Black Basta Black Basta
2025-03-10 ⋅ LevelBlue ⋅ Ken Ng
Prevent, Detect, Contain: LevelBlue MDR’s Guide Against Black Basta Affiliates’ Attacks
Black Basta Black Basta ReedBed
2025-03-06 ⋅ flare ⋅ Estelle Ruellan, Oleg Lypko, Tammy Harper
Deciphering Black Basta’s Infrastructure from the Chat Leak
Black Basta Black Basta
2025-03-05 ⋅ eSentire ⋅ Spence Hutchinson
Initial Takeaways from the Black Basta Chat Leaks
Black Basta Black Basta
2025-03-04 ⋅ Medium (A-poc) ⋅ A-poc
Black Basta Leak Analysis
Black Basta Black Basta
2025-03-03 ⋅ Trend Micro ⋅ Adam O'Connor, Catherine Loveria, Gabriel Cardoso, Ian Kenefick, Jack Walsh, Jovit Samaniego, Lucas Silva, Stephen Carbery
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
Black Basta Black Basta Cactus ReedBed
2025-03-02 ⋅ ropgadget.com ⋅ Jeff White
Pivoting on Black Basta's (leaked) Infrastructure
Black Basta Black Basta
2025-03-01 ⋅ ⋅ LeMagIT ⋅ Valéry Rieß-Marchive
Ransomware : de REvil à Black Basta, que sait-on de Tramp ?
Black Basta Black Basta
2025-02-28 ⋅ Intel 471 ⋅ Intel 471
Black Basta exposed: A look at a cybercrime data leak
Black Basta Black Basta
2025-02-28 ⋅ Medium walmartglobaltech ⋅ Joshua Platt
Agent AI, Basta Parser Extraordinaire
Black Basta Black Basta
2025-02-27 ⋅ BushidoToken ⋅ william thomas
BlackBasta Leaks: Lessons from the Ascension Health attack
Black Basta
2025-02-26 ⋅ Ontinue ⋅ Balazs Greksza, Domenico de Vitto, Manupriya Sharma, Rhys Downing
Inside BlackBasta: What Leaked Conversations Reveal About Their Ransomware Operations
Black Basta Black Basta
2025-02-22 ⋅ CrowdStrike ⋅ CrowdStrike
Wandering Spider
Black Basta Black Basta GOLD REBELLION
2025-01-31 ⋅ ConnectWise ⋅ Blake Eakin
Attackers Leveraging Microsoft Teams Defaults and Quick Assist for Social Engineering Attacks
Black Basta Black Basta ReedBed
2025-01-30 ⋅ eSentire ⋅ eSentire
Ongoing Email Bombing Campaigns leading to Remote Access and Post-Exploitation
Black Basta ReedBed UNC4393
2024-12-04 ⋅ Rapid7 ⋅ Tyler McGraw
Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware
Black Basta Cobalt Strike DarkGate SystemBC Zloader
2024-10-25 ⋅ Reliaquest ⋅ RELIAQUEST THREAT RESEARCH TEAM
ReliaQuest Uncovers New Black Basta Social Engineering Technique
Black Basta
2024-08-12 ⋅ Rapid7 ⋅ Tyler McGraw
Ongoing Social Engineering Campaign Refreshes Payloads
Black Basta Cobalt Strike GhostSocks Lumma Stealer SystemBC
2024-07-29 ⋅ Mandiant ⋅ Ashley Pearson, Jake Nicastro, Joseph Pisano, Josh Murchie, Joshua Shilko, Raymond Leong
UNC4393 Goes Gently into the SILENTNIGHT
Black Basta QakBot sRDI SystemBC Zloader UNC3973 UNC4393
2024-07-29 ⋅ Microsoft ⋅ Charles-Edouard Bettan, Danielle Kuznets Nohi, Edan Zwick, Meitar Pinto, Vaibhav Deshmukh
Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption
Black Basta Black Basta Storm-0506
2024-06-12 ⋅ Symantec ⋅ Symantec Threat Hunter Team
Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day
Black Basta
2024-06-12 ⋅ Symantec ⋅ Symantec Threat Hunter Team
Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day
Black Basta UNC4393
2024-05-15 ⋅ Stairwell ⋅ Threat Research at Stairwell
Stairwell threat report: Black Basta overview and detection rules
Black Basta Black Basta
2024-05-15 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Black Basta Cobalt Strike QakBot UNC4393
2024-05-15 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Black Basta Cobalt Strike QakBot SystemBC
2024-05-10 ⋅ Rapid7 Labs ⋅ Evan McCann, Thomas Elkins, Tyler McGraw
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators
Black Basta Black Basta Cobalt Strike NetSupportManager RAT
2024-05-10 ⋅ CISA ⋅ CISA
AA24-131A: #StopRansomware: Black Basta
Black Basta Black Basta
2024-02-28 ⋅ Security Intelligence ⋅ Golo Mühr, Ole Villadsen
X-Force data reveals top spam trends, campaigns and senior superlatives in 2023
404 Keylogger Agent Tesla Black Basta DarkGate Formbook IcedID Loki Password Stealer (PWS) Pikabot QakBot Remcos
2023-11-16 ⋅ YouTube (Swiss Cyber Storm) ⋅ Angelo Violetti
Resilience Rising: Countering the Threat Actors Behind Black Basta Ransomware
Black Basta
2023-06-27 ⋅ SecurityIntelligence ⋅ Charlotte Hammond, Ole Villadsen
The Trickbot/Conti Crypters: Where Are They Now?
Black Basta Conti Mount Locker PhotoLoader Royal Ransom SystemBC TrickBot
2023-04-19 ⋅ Bleeping Computer ⋅ Bill Toulas
March 2023 broke ransomware attack records with 459 incidents
Clop WhiteRabbit BianLian Black Basta BlackCat LockBit Medusa PLAY Royal Ransom
2023-04-18 ⋅ Mandiant ⋅ Mandiant
M-Trends 2023
QUIETEXIT AppleJeus Black Basta BlackCat CaddyWiper Cobalt Strike Dharma HermeticWiper Hive INDUSTROYER2 Ladon LockBit Meterpreter PartyTicket PlugX QakBot REvil Royal Ransom SystemBC WhisperGate
2023-03-30 ⋅ United States District Court (Eastern District of New York) ⋅ Fortra, HEALTH-ISAC, Microsoft
Cracked Cobalt Strike (1:23-cv-02447)
Black Basta BlackCat LockBit RagnarLocker LockBit Black Basta BlackCat Cobalt Strike Cuba Emotet LockBit Mount Locker PLAY QakBot RagnarLocker Royal Ransom Zloader
2023-03-20 ⋅ PWC ⋅ PWC
Cyber Threats 2022: A Year in Retrospect
Black Basta Black Basta Earth Lusca GOLD REBELLION
2023-03-15 ⋅ Reliaquest ⋅ RELIAQUEST THREAT RESEARCH TEAM
QBot: Laying the Foundations for Black Basta Ransomware Activity
Black Basta QakBot
2023-01-25 ⋅ Quadrant Information Security ⋅ Quadrant Information Security
Technical Analysis: Black Basta Malware Overview
Black Basta Black Basta
2023-01-23 ⋅ Kroll ⋅ Elio Biasiotto, Stephen Green
Black Basta – Technical Analysis
Black Basta Cobalt Strike MimiKatz QakBot SystemBC
2022-12-01 ⋅ Zscaler ⋅ Zscaler
Back in Black... Basta - Technical Analysis of BlackBasta Ransomware 2.0
Black Basta
2022-11-23 ⋅ Cybereason ⋅ Cybereason Global SOC Team
THREAT ALERT: Aggressive Qakbot Campaign and the Black Basta Ransomware Group Targeting U.S. Companies
Black Basta QakBot
2022-11-03 ⋅ SentinelOne ⋅ SentinelLabs
Black Basta Ransomware | Attacks deploy Custom EDR Evasion Tools tied to FIN7 Threat Actor
Black Basta QakBot SocksBot
2022-11-03 ⋅ Sentinel LABS ⋅ Antonio Cocomazzi
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
Black Basta
2022-10-12 ⋅ Trend Micro ⋅ Ian Kenefick, Lucas Silva, Nicole Hernandez
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike
Black Basta Brute Ratel C4 Cobalt Strike QakBot
2022-09-08 ⋅ Sentinel LABS ⋅ Aleksandar Milenkoski, Jim Walter
Crimeware Trends | Ransomware Developers Turn to Intermittent Encryption to Evade Detection
AgendaCrypt Black Basta BlackCat PLAY
2022-09-01 ⋅ Trend Micro ⋅ Trend Micro
Ransomware Spotlight Black Basta
Black Basta Cobalt Strike MimiKatz QakBot
2022-08-25 ⋅ Palo Alto Networks Unit 42 ⋅ Amer Elsad
Threat Assessment: Black Basta Ransomware
Black Basta QakBot
2022-08-25 ⋅ Palo Alto Networks Unit 42 ⋅ Amer Elsad
Threat Assessment: Black Basta Ransomware
Black Basta
2022-08-22 ⋅ Microsoft ⋅ Microsoft
Extortion Economics - Ransomware’s new business model
BlackCat Conti Hive REvil AgendaCrypt Black Basta BlackCat Brute Ratel C4 Cobalt Strike Conti Hive Mount Locker Nokoyawa Ransomware REvil Ryuk
2022-08-15 ⋅ SecurityScorecard ⋅ Vlad Pasca
A Deep Dive Into Black Basta Ransomware
Black Basta
2022-08-15 ⋅ SecurityScorecard ⋅ Vlad Pasca
A Deep Dive Into Black Basta Ransomware
Black Basta
2022-07-20 ⋅ Kaspersky ⋅ Dmitry Galov, Jornt van der Wiel, Marc Rivero López, Sergey Lozhkin
Luna and Black Basta — new ransomware for Windows, Linux and ESXi
Black Basta Conti
2022-06-30 ⋅ Trend Micro ⋅ Emmanuel Panopio, James Panlilio, John Kenneth Reyes, Kenneth Adrian Apostol, Melvin Singwa, Mirah Manlapig, Paolo Ronniel Labrador
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Black Basta Cobalt Strike QakBot
2022-06-28 ⋅ GBHackers on Security ⋅ Gurubaran S
Black Basta Ransomware Emerging From Underground to Attack Corporate Networks
Black Basta
2022-06-06 ⋅ NCC Group ⋅ Peter Gurney, Ross Inman
Shining the Light on Black Basta
Black Basta
2022-06-01 ⋅ Avertium ⋅ Avertium
An In-Depth Look At Black Basta Ransomware
Black Basta
2022-05-26 ⋅ IBM ⋅ Dave McMillen, Kevin Henson
Black Basta Besting Your Network?
Black Basta
2022-05-20 ⋅ AdvIntel ⋅ Marley Smith, Vitali Kremez, Yelisey Boguslavskiy
DisCONTInued: The End of Conti’s Brand Marks New Chapter For Cybercrime Landscape
AvosLocker Black Basta BlackByte BlackCat Conti HelloKitty Hive
2022-05-09 ⋅ Trend Micro ⋅ Ieriz Nicolle Gonzalez, Ivan Nicole Chavez, Katherine Casona, Nathaniel Morales
Examining the Black Basta Ransomware’s Infection Routine
Black Basta
2022-04-29 ⋅ The Record ⋅ Jonathan Greig
German wind farm operator confirms cybersecurity incident
Black Basta BlackCat
2022-04-27 ⋅ BleepingComputer ⋅ BleepingComputer
New Black Basta ransomware springs into action with a dozen breaches
Black Basta
2022-04-26 ⋅ Bleeping Computer ⋅ Lawrence Abrams
American Dental Association hit by new Black Basta ransomware
Black Basta
Yara Rules
[TLP:WHITE] win_blackbasta_auto (20260917 | Detects win.blackbasta.)
rule win_blackbasta_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.blackbasta."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 8a4304 88459e 668b4306 66894598 8d4598 50 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8a4304               | mov                 al, byte ptr [ebx + 4]
            //   88459e               | mov                 byte ptr [ebp - 0x62], al
            //   668b4306             | mov                 ax, word ptr [ebx + 6]
            //   66894598             | mov                 word ptr [ebp - 0x68], ax
            //   8d4598               | lea                 eax, [ebp - 0x68]
            //   50                   | push                eax

        $sequence_1 = { 894514 8955c8 3b45ec 72c1 8b7df0 8b4dec }
            // n = 6, score = 100
            //   894514               | mov                 dword ptr [ebp + 0x14], eax
            //   8955c8               | mov                 dword ptr [ebp - 0x38], edx
            //   3b45ec               | cmp                 eax, dword ptr [ebp - 0x14]
            //   72c1                 | jb                  0xffffffc3
            //   8b7df0               | mov                 edi, dword ptr [ebp - 0x10]
            //   8b4dec               | mov                 ecx, dword ptr [ebp - 0x14]

        $sequence_2 = { 8975e8 c645fc01 85f6 0f84f0000000 8b4508 8b4804 85c9 }
            // n = 7, score = 100
            //   8975e8               | mov                 dword ptr [ebp - 0x18], esi
            //   c645fc01             | mov                 byte ptr [ebp - 4], 1
            //   85f6                 | test                esi, esi
            //   0f84f0000000         | je                  0xf6
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   8b4804               | mov                 ecx, dword ptr [eax + 4]
            //   85c9                 | test                ecx, ecx

        $sequence_3 = { 8bf0 c7458c00000000 6a18 8d458c c7459c00000000 56 50 }
            // n = 7, score = 100
            //   8bf0                 | mov                 esi, eax
            //   c7458c00000000       | mov                 dword ptr [ebp - 0x74], 0
            //   6a18                 | push                0x18
            //   8d458c               | lea                 eax, [ebp - 0x74]
            //   c7459c00000000       | mov                 dword ptr [ebp - 0x64], 0
            //   56                   | push                esi
            //   50                   | push                eax

        $sequence_4 = { ff5228 8b5608 8d4e08 8bf8 897de8 }
            // n = 5, score = 100
            //   ff5228               | call                dword ptr [edx + 0x28]
            //   8b5608               | mov                 edx, dword ptr [esi + 8]
            //   8d4e08               | lea                 ecx, [esi + 8]
            //   8bf8                 | mov                 edi, eax
            //   897de8               | mov                 dword ptr [ebp - 0x18], edi

        $sequence_5 = { e9???????? 8b4dbc e9???????? 8d8dd8feffff e9???????? 8d8dd8feffff e9???????? }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8b4dbc               | mov                 ecx, dword ptr [ebp - 0x44]
            //   e9????????           |                     
            //   8d8dd8feffff         | lea                 ecx, [ebp - 0x128]
            //   e9????????           |                     
            //   8d8dd8feffff         | lea                 ecx, [ebp - 0x128]
            //   e9????????           |                     

        $sequence_6 = { e9???????? 8b4dd8 e9???????? 8b4dd8 e9???????? 8b4dbc e9???????? }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8b4dd8               | mov                 ecx, dword ptr [ebp - 0x28]
            //   e9????????           |                     
            //   8b4dd8               | mov                 ecx, dword ptr [ebp - 0x28]
            //   e9????????           |                     
            //   8b4dbc               | mov                 ecx, dword ptr [ebp - 0x44]
            //   e9????????           |                     

        $sequence_7 = { e8???????? 8bb5e4feffff 8d8de4feffff 8b4620 ffd0 50 8b4310 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8bb5e4feffff         | mov                 esi, dword ptr [ebp - 0x11c]
            //   8d8de4feffff         | lea                 ecx, [ebp - 0x11c]
            //   8b4620               | mov                 eax, dword ptr [esi + 0x20]
            //   ffd0                 | call                eax
            //   50                   | push                eax
            //   8b4310               | mov                 eax, dword ptr [ebx + 0x10]

        $sequence_8 = { 8b7304 c645fc0d 3b7308 7444 8d4504 897550 50 }
            // n = 7, score = 100
            //   8b7304               | mov                 esi, dword ptr [ebx + 4]
            //   c645fc0d             | mov                 byte ptr [ebp - 4], 0xd
            //   3b7308               | cmp                 esi, dword ptr [ebx + 8]
            //   7444                 | je                  0x46
            //   8d4504               | lea                 eax, [ebp + 4]
            //   897550               | mov                 dword ptr [ebp + 0x50], esi
            //   50                   | push                eax

        $sequence_9 = { ff7574 c7456800000000 8b4e14 897560 e8???????? 8b4e14 8ad8 }
            // n = 7, score = 100
            //   ff7574               | push                dword ptr [ebp + 0x74]
            //   c7456800000000       | mov                 dword ptr [ebp + 0x68], 0
            //   8b4e14               | mov                 ecx, dword ptr [esi + 0x14]
            //   897560               | mov                 dword ptr [ebp + 0x60], esi
            //   e8????????           |                     
            //   8b4e14               | mov                 ecx, dword ptr [esi + 0x14]
            //   8ad8                 | mov                 bl, al

    condition:
        7 of them and filesize < 1758208
}
[TLP:WHITE] win_blackbasta_w0   (20220722 | Black Basta is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.)
rule win_blackbasta_w0 {
   meta:
      description = "Black Basta is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates."
      author = "rcoliveira@protonmail.com"
      reference_1 = "https://securelist.com/luna-black-basta-ransomware/106950/"
      reference_2 = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta"
      hash_1 = "96339a7e87ffce6ced247feb9b4cb7c05b83ca315976a9522155bad726b8e5be"
      hash_2 = "0d6c3de5aebbbe85939d7588150edf7b7bdc712fceb6a83d79e65b6f79bfc2ef"
      date = "2022-07-21"
      sharing = "TLP:WHITE"
      malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta"
      malpedia_version = "20220722"
      malpedia_license = "CC BY-NC-SA 4.0"
      malpedia_sharing = "TLP:WHITE"
   strings:
      $s1 = "aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion" fullword ascii
      $s2 = "Your data are stolen and encrypted" fullword ascii
      $s3 = "The data will be published on TOR website if you do not pay the ransom" fullword ascii
      $s4 = "Input is not valid base64-encoded data." fullword ascii
      $s5 = "(you should download and install TOR browser first https://torproject.org)" fullword ascii
      $a1 = "_Z12EncryptBytesP8Chacha20PhS1_S1_i" fullword ascii
      $a2 = "_Z21GetEncryptedNextBlockP8Chacha20PN3ghc10filesystem13basic_fstreamIcSt11char_traitsIcEEEPhS8_ixS8_" fullword ascii /* score: '17.00'*/
      $a3 = "_ZNSt10_HashtableISsSt4pairIKSsPcESaIS3_ENSt8__detail10_Select1stESt8equal_toISsESt4hashISsENS5_18_Mod_range_hashingENS5_20_Default_ranged_hashENS5_20_Prime_rehash_policyENS5_17_Hashtable_traitsILb1ELb0ELb1EEEE21_M_insert_unique_nodeEmmPNS5_10_Hash_nodeIS3_Lb1EEE" fullword ascii
      $a4 = "_ZNSt8__detail9_Map_baseISsSt4pairIKSsPcESaIS4_ENS_10_Select1stESt8equal_toISsESt4hashISsENS_18_Mod_range_hashingENS_20_Default_ranged_hashENS_20_Prime_rehash_policyENS_17_Hashtable_traitsILb1ELb0ELb1EEELb1EEixEOSs" fullword ascii
      $a5 = "_ZN3ghc10filesystem4path28postprocess_path_with_formatENS1_6formatE" fullword ascii
      $a6 = "C:/Users/dssd/Desktop/src" fullword ascii
      $a7 = "totalBytesEncrypted" fullword ascii
   condition:
      filesize < 600KB and
      (1 of ($s*) and 1 of ($a*) ) or (8 of them)
}
Download all Yara Rules