Actor(s): Silent Chollima
There is no description at this point.
rule win_andardoor_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.andardoor." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.andardoor" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { f20f59d7 f20f59d7 f20f59d7 66490f7ed0 } // n = 4, score = 200 // f20f59d7 | dec eax // f20f59d7 | inc ecx // f20f59d7 | jne 0xe // 66490f7ed0 | xor al, al $sequence_1 = { 0f1f4000 40383d???????? 7517 b9c8000000 ff15???????? 488b1d???????? } // n = 6, score = 200 // 0f1f4000 | test cx, cx // 40383d???????? | // 7517 | jne 0x235 // b9c8000000 | xor edi, edi // ff15???????? | // 488b1d???????? | $sequence_2 = { 488bc3 488bbc2410040000 488b8dc0020000 4833cc e8???????? } // n = 5, score = 200 // 488bc3 | movzx esi, byte ptr [edx + eax*4 + 0x18593] // 488bbc2410040000 | mov ebx, ecx // 488b8dc0020000 | mov edi, eax // 4833cc | inc ecx // e8???????? | $sequence_3 = { 4c896c2420 ff5018 85c0 7434 488b4d88 } // n = 5, score = 200 // 4c896c2420 | je 0xa17 // ff5018 | dec eax // 85c0 | lea eax, [0x58a8] // 7434 | dec eax // 488b4d88 | cmp ecx, eax $sequence_4 = { 48899c2480400000 4889bc2498400000 4c89bc2460400000 4983cfff } // n = 4, score = 200 // 48899c2480400000 | dec eax // 4889bc2498400000 | add ebx, 8 // 4c89bc2460400000 | dec eax // 4983cfff | lea eax, [0x12160] $sequence_5 = { ff15???????? 488b0d???????? ff15???????? 33c0 eb47 488b442468 } // n = 6, score = 200 // ff15???????? | // 488b0d???????? | // ff15???????? | // 33c0 | cmp eax, 1 // eb47 | sete al // 488b442468 | jmp 0x5be $sequence_6 = { 4803d6 4533c9 ff15???????? 85c0 7e25 b905000000 03d8 } // n = 7, score = 200 // 4803d6 | xor al, al // 4533c9 | jmp 0xb8 // ff15???????? | // 85c0 | mov al, 1 // 7e25 | dec eax // b905000000 | mov ebp, dword ptr [esp + 0x30] // 03d8 | xor al, al $sequence_7 = { 40887dc8 488945c9 8bdf 488945d1 668945d9 } // n = 5, score = 200 // 40887dc8 | inc ebp // 488945c9 | xor ecx, ecx // 8bdf | dec eax // 488945d1 | lea edx, [0x1121c] // 668945d9 | dec eax $sequence_8 = { 7507 33c0 e9???????? 4889bc24600d0000 ba00040000 4c89bc24680d0000 } // n = 6, score = 200 // 7507 | mov ebx, ecx // 33c0 | sub edx, 1 // e9???????? | // 4889bc24600d0000 | je 0x7be // ba00040000 | cmp edx, 1 // 4c89bc24680d0000 | jne 0x7f6 $sequence_9 = { 0f85c5000000 0fb74c4202 66413b4c4002 0f85b4000000 } // n = 4, score = 200 // 0f85c5000000 | lea ecx, [0x1a75b] // 0fb74c4202 | nop word ptr [eax + eax] // 66413b4c4002 | xor edx, edx // 0f85b4000000 | je 0xb7 condition: 7 of them and filesize < 339968 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY