There is no description at this point.
rule win_aperetif_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.aperetif." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.aperetif" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { ffb424a80c0000 53 e8???????? 55 53 e8???????? ff742460 } // n = 7, score = 100 // ffb424a80c0000 | push dword ptr [esp + 0xca8] // 53 | push ebx // e8???????? | // 55 | push ebp // 53 | push ebx // e8???????? | // ff742460 | push dword ptr [esp + 0x60] $sequence_1 = { 895dc8 c745fc01000000 c745d000000000 c745d400000000 85db 740a f0ff4308 } // n = 7, score = 100 // 895dc8 | mov dword ptr [ebp - 0x38], ebx // c745fc01000000 | mov dword ptr [ebp - 4], 1 // c745d000000000 | mov dword ptr [ebp - 0x30], 0 // c745d400000000 | mov dword ptr [ebp - 0x2c], 0 // 85db | test ebx, ebx // 740a | je 0xc // f0ff4308 | lock inc dword ptr [ebx + 8] $sequence_2 = { b999030000 51 68???????? 50 6891000000 6a10 e8???????? } // n = 7, score = 100 // b999030000 | mov ecx, 0x399 // 51 | push ecx // 68???????? | // 50 | push eax // 6891000000 | push 0x91 // 6a10 | push 0x10 // e8???????? | $sequence_3 = { 8d8424dc170000 50 56 ff742428 8d842448040000 688c000000 50 } // n = 7, score = 100 // 8d8424dc170000 | lea eax, [esp + 0x17dc] // 50 | push eax // 56 | push esi // ff742428 | push dword ptr [esp + 0x28] // 8d842448040000 | lea eax, [esp + 0x448] // 688c000000 | push 0x8c // 50 | push eax $sequence_4 = { c745fc00000000 85c9 7409 8d450c 50 e8???????? 8b4e0c } // n = 7, score = 100 // c745fc00000000 | mov dword ptr [ebp - 4], 0 // 85c9 | test ecx, ecx // 7409 | je 0xb // 8d450c | lea eax, [ebp + 0xc] // 50 | push eax // e8???????? | // 8b4e0c | mov ecx, dword ptr [esi + 0xc] $sequence_5 = { eb06 c70600000000 c6460401 0fb74e06 8d45b8 663908 740a } // n = 7, score = 100 // eb06 | jmp 8 // c70600000000 | mov dword ptr [esi], 0 // c6460401 | mov byte ptr [esi + 4], 1 // 0fb74e06 | movzx ecx, word ptr [esi + 6] // 8d45b8 | lea eax, [ebp - 0x48] // 663908 | cmp word ptr [eax], cx // 740a | je 0xc $sequence_6 = { f00fc14104 7515 8b01 ff10 8b4dc4 8bc6 f00fc14108 } // n = 7, score = 100 // f00fc14104 | lock xadd dword ptr [ecx + 4], eax // 7515 | jne 0x17 // 8b01 | mov eax, dword ptr [ecx] // ff10 | call dword ptr [eax] // 8b4dc4 | mov ecx, dword ptr [ebp - 0x3c] // 8bc6 | mov eax, esi // f00fc14108 | lock xadd dword ptr [ecx + 8], eax $sequence_7 = { e9???????? 8d4d58 e9???????? 8d4d2c e9???????? 8b542408 8d420c } // n = 7, score = 100 // e9???????? | // 8d4d58 | lea ecx, [ebp + 0x58] // e9???????? | // 8d4d2c | lea ecx, [ebp + 0x2c] // e9???????? | // 8b542408 | mov edx, dword ptr [esp + 8] // 8d420c | lea eax, [edx + 0xc] $sequence_8 = { eb0d 0fb74706 c70700000000 0fb7c0 c6470401 0fb7c8 663b4d48 } // n = 7, score = 100 // eb0d | jmp 0xf // 0fb74706 | movzx eax, word ptr [edi + 6] // c70700000000 | mov dword ptr [edi], 0 // 0fb7c0 | movzx eax, ax // c6470401 | mov byte ptr [edi + 4], 1 // 0fb7c8 | movzx ecx, ax // 663b4d48 | cmp cx, word ptr [ebp + 0x48] $sequence_9 = { e8???????? b8cc000000 c645fc06 66a3???????? b9???????? 6a0a 33c0 } // n = 7, score = 100 // e8???????? | // b8cc000000 | mov eax, 0xcc // c645fc06 | mov byte ptr [ebp - 4], 6 // 66a3???????? | // b9???????? | // 6a0a | push 0xa // 33c0 | xor eax, eax condition: 7 of them and filesize < 10500096 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY