YARA rule 'ransomware_behavior': Ransomware-like patterns (mass encryption, ransom notes) [malware]
Critical
- Category
- YARA Match
- Content
see full transaction history of that address — each receive should use a fresh address - Clipboard malware silently replaces copied addresses — always verify first and last 6 characters match on both devices before confirming send - Hardware wallet "verify on device" step is critical — if malware changed the address, only the device screen shows the real destination ## Scam Recognition - "Send X BTC, receive 2X back" is always a scam — no exceptions, even if the account looks official - "Recovery services" that ask for seed phrase will steal everything — legitimate recovery never needs the seed - Fake wallet apps in app stores with slight name variations — verify publisher and download count before recommending - "Support" DMing users on social media asking to "validate wallet" or "sync" — real support never initiates contact ## Verification APIs - mempool.space is the current standard block explorer — blockchain.info is outdated and less reliable for fee data - Tran
- Confidence
- 80% confidence
- Finding
- YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
