MalwareBazaar Database
This page shows some basic information the YARA rule INDICATOR_SUSPICIOUS_USNDeleteJournal
including corresponding malware samples.
Database Entry
YARA Rule: | INDICATOR_SUSPICIOUS_USNDeleteJournal |
---|---|
Author: | ditekSHen |
Description: | Detects executables containing anti-forensic artifcats of deletiing USN change journal. Observed in ransomware |
Firstseen: | 2021-03-24 15:11:38 UTC |
Lastseen: | 2025-07-31 20:06:32 UTC |
Sightings: | 152 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
---|