RULE(RULE ID:105499)

Rule General Information
Release Date: 2020-12-14
Rule Name: Ransomware Activity: Possible WannaCry DNS Lookup 1
Severity:
CVE ID:
Rule Protection Details
Description: Ransomware uses various encryption algorithms to encrypt files, and the infected person generally cannot decrypt them, and must get the decrypted private key to crack them. The rules for detection of malicious domain name www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com DNS request.
Impact: This virus uses various encryption algorithms to encrypt the file. The infected person can't decrypt the file without decrypted private key.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, Other Unix, Linux
Reference:
Solutions
Search and kill the malware by using antivirus tools and repair the system vulnerabilities.