Actor(s): Silent Chollima
There is no description at this point.
rule win_atharvan_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.atharvan." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.atharvan" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 660f1f440000 80f1ab 418808 4d8d4001 } // n = 4, score = 100 // 660f1f440000 | dec eax // 80f1ab | lea ecx, [0x15b91] // 418808 | dec eax // 4d8d4001 | mov eax, dword ptr [ebp - 0x28] $sequence_1 = { 488d4901 0fb601 84c0 75f1 488d542420 488bcb e8???????? } // n = 7, score = 100 // 488d4901 | dec esp // 0fb601 | mov dword ptr [esp + 0x90], esi // 84c0 | add ecx, 1 // 75f1 | dec eax // 488d542420 | mov eax, 0xffffffff // 488bcb | test eax, eax // e8???????? | $sequence_2 = { 4833c4 48898550030000 488bf2 488bf9 33d2 488d8d40020000 41b804010000 } // n = 7, score = 100 // 4833c4 | mov dword ptr [ebx + 0x224], 0x14 // 48898550030000 | dec eax // 488bf2 | mov eax, ebx // 488bf9 | mov dword ptr [ebx + 0x22c], 0 // 33d2 | movups xmmword ptr [ebx + 0x230], xmm0 // 488d8d40020000 | movups xmmword ptr [ebx + 0x240], xmm0 // 41b804010000 | movups xmmword ptr [ebx + 0x250], xmm0 $sequence_3 = { 4b87bcfeb05c0200 33c0 488b5c2450 488b6c2458 488b742460 4883c420 } // n = 6, score = 100 // 4b87bcfeb05c0200 | inc eax // 33c0 | dec eax // 488b5c2450 | lea ecx, [ebp - 8] // 488b6c2458 | dec eax // 488b742460 | lea edx, [0x1c6b5] // 4883c420 | dec eax $sequence_4 = { eb42 85c9 782e 3b0d???????? 7326 4863c9 488d15cc0b0100 } // n = 7, score = 100 // eb42 | add esp, 0x20 // 85c9 | je 0x14c1 // 782e | mov al, 1 // 3b0d???????? | // 7326 | dec eax // 4863c9 | add esp, 0x28 // 488d15cc0b0100 | ret $sequence_5 = { ff15???????? 488b4d88 33d2 ff15???????? } // n = 4, score = 100 // ff15???????? | // 488b4d88 | dec eax // 33d2 | lea edi, [0x132a0] // ff15???????? | $sequence_6 = { 7418 660f1f840000000000 34ab 8801 488d4901 0fb601 } // n = 6, score = 100 // 7418 | sub al, 0 // 660f1f840000000000 | add cl, bh // 34ab | sub al, 0 // 8801 | add byte ptr [eax], dh // 488d4901 | sub dword ptr [eax], eax // 0fb601 | add byte ptr [ebp - 0x20ffffd5], bl $sequence_7 = { 48c1e602 0fb784b990a90100 488d9180a00100 488d8d24030000 } // n = 4, score = 100 // 48c1e602 | dec esp // 0fb784b990a90100 | lea esi, [0x10512] // 488d9180a00100 | and eax, 0x3f // 488d8d24030000 | dec eax $sequence_8 = { 488b4530 488b8888000000 488d053a2f0100 483bc8 7405 e8???????? c70301000000 } // n = 7, score = 100 // 488b4530 | mov byte ptr [eax], cl // 488b8888000000 | dec esp // 488d053a2f0100 | lea eax, [0xa0bf] // 483bc8 | dec eax // 7405 | mov edx, ebx // e8???????? | // c70301000000 | mov ecx, edi $sequence_9 = { 488d4c2448 c7442449a1efc4dc c744244dc5c7c4ca c7442451cf8bfbca c7442455d9cac6ce } // n = 5, score = 100 // 488d4c2448 | add byte ptr [eax], dh // c7442449a1efc4dc | sub dword ptr [eax], eax // c744244dc5c7c4ca | add byte ptr [ebp - 0x20ffffd5], bl // c7442451cf8bfbca | sub al, 0 // c7442455d9cac6ce | sub al, 0 condition: 7 of them and filesize < 348160 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY