Bart Retweeted Microsoft Security Intelligence
Simple Yara rule for the #DearCry ransomware reportedly attacking unpatched Exchange servers:
https://github.com/bartblaze/Yara-rules/blob/master/rules/ransomware/DearCry.yar …
Ref:https://twitter.com/MsftSecIntel/status/1370236539427459076 …
Bart added,
Microsoft Security IntelligenceVerified account @MsftSecIntel
We have detected and are now blocking a new family of ransomware being used after an initial compromise of unpatched on-premises Exchange Servers. Microsoft protects against this threat known as Ransom:Win32/DoejoCrypt.A, and also as DearCry.
Show this thread
11:47 PM - 11 Mar 2021
0 replies
4 retweets
8 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.