SYMBOLCOMMON_NAMEaka. SYNONYMS
win.acbackdoor (Back to overview)

ACBackdoor

VTCollection    

A Linux backdoor that was apparently ported to Windows. This entry represents the Windows version. It appears the Linux version was written first and the Windows version was ported later, without full functionality. The Linux version offers persistence as well as some process manipulation techniques, though both versions apparently offer the ability to access the command line and execute programs as well as self-update.

References
2019-11-18 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Linux, Windows Users Targeted With New ACBackdoor Malware
ACBackdoor ACBackdoor
Yara Rules
[TLP:WHITE] win_acbackdoor_auto (20260917 | Detects win.acbackdoor.)
rule win_acbackdoor_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.acbackdoor."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acbackdoor"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c744240c33170000 c7442408???????? c744240401000000 891c24 e8???????? e9???????? 55 }
            // n = 7, score = 100
            //   c744240c33170000     | mov                 dword ptr [esp + 0xc], 0x1733
            //   c7442408????????     |                     
            //   c744240401000000     | mov                 dword ptr [esp + 4], 1
            //   891c24               | mov                 dword ptr [esp], ebx
            //   e8????????           |                     
            //   e9????????           |                     
            //   55                   | push                ebp

        $sequence_1 = { c744240c13040000 e9???????? 8b06 83780c07 0f8422020000 c7875c040000803c4300 c7875404000000394300 }
            // n = 7, score = 100
            //   c744240c13040000     | mov                 dword ptr [esp + 0xc], 0x413
            //   e9????????           |                     
            //   8b06                 | mov                 eax, dword ptr [esi]
            //   83780c07             | cmp                 dword ptr [eax + 0xc], 7
            //   0f8422020000         | je                  0x228
            //   c7875c040000803c4300     | mov    dword ptr [edi + 0x45c], 0x433c80
            //   c7875404000000394300     | mov    dword ptr [edi + 0x454], 0x433900

        $sequence_2 = { e9???????? 8b9c24c0000000 c7442410399c4a00 bd8086ffff c744240c46050000 c7442408???????? c744240401000000 }
            // n = 7, score = 100
            //   e9????????           |                     
            //   8b9c24c0000000       | mov                 ebx, dword ptr [esp + 0xc0]
            //   c7442410399c4a00     | mov                 dword ptr [esp + 0x10], 0x4a9c39
            //   bd8086ffff           | mov                 ebp, 0xffff8680
            //   c744240c46050000     | mov                 dword ptr [esp + 0xc], 0x546
            //   c7442408????????     |                     
            //   c744240401000000     | mov                 dword ptr [esp + 4], 1

        $sequence_3 = { c78424a000000007d57c36 c78424a40000002a299a62 c78424a800000017dd7030 c78424ac0000005a015991 c78424b000000039590ef7 c78424b4000000d8ec2f15 c78424b8000000310bc0ff }
            // n = 7, score = 100
            //   c78424a000000007d57c36     | mov    dword ptr [esp + 0xa0], 0x367cd507
            //   c78424a40000002a299a62     | mov    dword ptr [esp + 0xa4], 0x629a292a
            //   c78424a800000017dd7030     | mov    dword ptr [esp + 0xa8], 0x3070dd17
            //   c78424ac0000005a015991     | mov    dword ptr [esp + 0xac], 0x9159015a
            //   c78424b000000039590ef7     | mov    dword ptr [esp + 0xb0], 0xf70e5939
            //   c78424b4000000d8ec2f15     | mov    dword ptr [esp + 0xb4], 0x152fecd8
            //   c78424b8000000310bc0ff     | mov    dword ptr [esp + 0xb8], 0xffc00b31

        $sequence_4 = { d3e0 a882 7517 ba08000000 f6c406 750d 83e01c }
            // n = 7, score = 100
            //   d3e0                 | shl                 eax, cl
            //   a882                 | test                al, 0x82
            //   7517                 | jne                 0x19
            //   ba08000000           | mov                 edx, 8
            //   f6c406               | test                ah, 6
            //   750d                 | jne                 0xf
            //   83e01c               | and                 eax, 0x1c

        $sequence_5 = { e8???????? 8b842470020000 85c0 0f85a6020000 8b842470020000 b962000000 89ef }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8b842470020000       | mov                 eax, dword ptr [esp + 0x270]
            //   85c0                 | test                eax, eax
            //   0f85a6020000         | jne                 0x2ac
            //   8b842470020000       | mov                 eax, dword ptr [esp + 0x270]
            //   b962000000           | mov                 ecx, 0x62
            //   89ef                 | mov                 edi, ebp

        $sequence_6 = { e8???????? 8b4308 85c0 0f84d4020000 8b542430 31c9 89d8 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8b4308               | mov                 eax, dword ptr [ebx + 8]
            //   85c0                 | test                eax, eax
            //   0f84d4020000         | je                  0x2da
            //   8b542430             | mov                 edx, dword ptr [esp + 0x30]
            //   31c9                 | xor                 ecx, ecx
            //   89d8                 | mov                 eax, ebx

        $sequence_7 = { e8???????? 85c0 0f8879ffffff 8d543d00 01d0 e9???????? 8d442444 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   85c0                 | test                eax, eax
            //   0f8879ffffff         | js                  0xffffff7f
            //   8d543d00             | lea                 edx, [ebp + edi]
            //   01d0                 | add                 eax, edx
            //   e9????????           |                     
            //   8d442444             | lea                 eax, [esp + 0x44]

        $sequence_8 = { e8???????? 83c001 890424 ff15???????? 89c3 85c0 0f84c6000000 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   83c001               | add                 eax, 1
            //   890424               | mov                 dword ptr [esp], eax
            //   ff15????????         |                     
            //   89c3                 | mov                 ebx, eax
            //   85c0                 | test                eax, eax
            //   0f84c6000000         | je                  0xcc

        $sequence_9 = { e8???????? 897c2404 891c24 e8???????? 891c24 ffd6 83ec04 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   897c2404             | mov                 dword ptr [esp + 4], edi
            //   891c24               | mov                 dword ptr [esp], ebx
            //   e8????????           |                     
            //   891c24               | mov                 dword ptr [esp], ebx
            //   ffd6                 | call                esi
            //   83ec04               | sub                 esp, 4

    condition:
        7 of them and filesize < 1704960
}
Download all Yara Rules