alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Possible unknown strain ransomware extension or note detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE WonderCrypter ransomware extension or note detected.`; pcre: `/ 4663: 567: 5145: /`; pcre...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Zeta ransomware note detected.`; pcre: `/ 4663: 567: 5145: /`; content: `HELP YOUR FILES...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE WonderCrypter ransomware extension or note detected.`; pcre: `/ 4663: 567: 5145: /`; pcre...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Alpha ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.encrypt...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Mobef ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content: `....
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE El Polocker ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.ha...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CTB Locker ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.ctbl...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Cryaki ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.scl `...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CryptFIle2 ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.scl...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE XRTN ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.CrySiS...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Xorist ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content: `....
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Virus Encoder ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Zlader / Russian or VaultCrypt ransomware extension detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Troldesh ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE TeslaCrypt 3.0 ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE TeslaCrypt 0.x 2.2.0 ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Surprise ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.suprise...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Sport ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.sport...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Sanction ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.sanction...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE LowLevel04 ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.oor...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Samas Samsam ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Rokku ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.rokku...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE RemindMe ransomware extension or note detected.`; pcre: `/ 4663: 567: 5145: /`; pcre:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Coverton or Torrentlocker ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Radamant ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.RADAMANT...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE OMG! ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.LOL! `;...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Offline ransomware ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Nemucod ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.crypted...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE MireWare ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.fucked...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Magic ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.magic...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE LeChiffre ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.lechiffre...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE KimcilWare ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content: `.kimcilware...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE KeyBTC Win32/Isda BAT/Xibow ransomware extension detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE EDA2,HiddenTear,Job Crypter,KimcilWare,SkidLocker,Pompous,Strictor or Rakhni ransomware extension...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Jigsaw MSIL/JigsawLocker.A`; pcre: `/ 4663: 567: 5145: /`; meta content: `. `, btc,kkk...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE iLock, iLockLight or Lortok ransomware extension detected.`; pcre: `/ 4663: 567: 5145:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Hi Buddy! or Rakhni ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CryptXXX or Gomasom ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CryptoTorLocker2015 ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CryptInfinite ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE CryptInfinite ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Coverton ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; meta content:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Chimera Win32/Chicrypt ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Cerber Win32/Cerber ransomware extension detected.`; pcre: `/ 4663: 567: 5145: /`; content...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE Win32/Cribit or MSIL/Vaultlock.A ransomware extension detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE 7ev3n Ransom:Win32/Empercrypt.A ransomware extension detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE .CryptoHasYou. Trojan:Win32/Dynamerac ransom note detected.`; pcre: `/ 4663: 567:...
alert syslog $EXTERNAL NET any $HOME NET any (msg:` WINDOWS MALWARE TrueCrypter Rakhni or .CryptoHasYou. Trojan:Win32/Dynamerac ransomware extension detected...
alert syslog $EXTERNAL NET any $HOME NET any (msg: ` WINDOWS MISC Installation of new service via Security Audit `; pcre: `/ 4697: 601: /`; classtype: suspicious...