Common Information
Type Value
Value
rule M_Disrupt_ROADSWEEP_1 {
	meta:
		author = "Mandiant"
		description = "Identifies the encryption key used within ROADSWEEP"
	strings:
		$ = { C6 45 D5 E4 C6 45 D6 B1 C6 45 D7 6B C6 45 D8 22 C6 45 D9 B5 C6 45 DA 88 C6 45 DB 94 C6 45 DC AA C6 45 DD 86 C6 45 DE C4 C6 45 DF 21 C6 45 E0 E8 C6 45 E1 75 C6 45 E2 9D C6 45 E3 F3 C7 44 24 10 00 00 00 F0 }
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2022-08-04 92 ROADSWEEP Ransomware Targets the Albanian Government