SYMBOLCOMMON_NAMEaka. SYNONYMS
win.badhatch (Back to overview)

BADHATCH

Actor(s): FIN8

VTCollection    

There is no description at this point.

References
2021-08-15 ⋅ Symantec ⋅ Threat Hunter Team
The Ransomware Threat
Babuk BlackMatter DarkSide Avaddon Babuk BADHATCH BazarBackdoor BlackMatter Clop Cobalt Strike Conti DarkSide DoppelPaymer Egregor Emotet FiveHands FriedEx Hades IcedID LockBit Maze MegaCortex MimiKatz QakBot RagnarLocker REvil Ryuk TrickBot WastedLocker
2021-03-15 ⋅ Team Cymru ⋅ Josh Hopkins
FIN8: BADHATCH Threat Indicator Enrichmen
BADHATCH
2021-03-10 ⋅ Bitdefender ⋅ Bogdan Botezatu, Victor Vrabie
FIN8 Returns with Improved BADHATCH Toolkit
BADHATCH
2019-07-23 ⋅ Gigamon ⋅ Ed Miles, Justin Warner, Kristina Savelesky
ABADBABE 8BADF00D: Discovering BADHATCH and a Detailed Look at FIN8’s Tooling
BADHATCH
Yara Rules
[TLP:WHITE] win_badhatch_auto (20260917 | Detects win.badhatch.)
rule win_badhatch_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.badhatch."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badhatch"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b7dc4 8d8568dfffff 2bf8 8d443f02 50 6a00 ff35???????? }
            // n = 7, score = 100
            //   8b7dc4               | mov                 edi, dword ptr [ebp - 0x3c]
            //   8d8568dfffff         | lea                 eax, [ebp - 0x2098]
            //   2bf8                 | sub                 edi, eax
            //   8d443f02             | lea                 eax, [edi + edi + 2]
            //   50                   | push                eax
            //   6a00                 | push                0
            //   ff35????????         |                     

        $sequence_1 = { 53 e8???????? 33c9 83c40c 8bf0 }
            // n = 5, score = 100
            //   53                   | push                ebx
            //   e8????????           |                     
            //   33c9                 | xor                 ecx, ecx
            //   83c40c               | add                 esp, 0xc
            //   8bf0                 | mov                 esi, eax

        $sequence_2 = { e8???????? 83c41c 8bf8 8b75fc e8???????? 8bc7 5f }
            // n = 7, score = 100
            //   e8????????           |                     
            //   83c41c               | add                 esp, 0x1c
            //   8bf8                 | mov                 edi, eax
            //   8b75fc               | mov                 esi, dword ptr [ebp - 4]
            //   e8????????           |                     
            //   8bc7                 | mov                 eax, edi
            //   5f                   | pop                 edi

        $sequence_3 = { ff35???????? c745fc08000000 c745e401000000 c745e810270000 c745ece8030000 c745f4e0930400 8975f8 }
            // n = 7, score = 100
            //   ff35????????         |                     
            //   c745fc08000000       | mov                 dword ptr [ebp - 4], 8
            //   c745e401000000       | mov                 dword ptr [ebp - 0x1c], 1
            //   c745e810270000       | mov                 dword ptr [ebp - 0x18], 0x2710
            //   c745ece8030000       | mov                 dword ptr [ebp - 0x14], 0x3e8
            //   c745f4e0930400       | mov                 dword ptr [ebp - 0xc], 0x493e0
            //   8975f8               | mov                 dword ptr [ebp - 8], esi

        $sequence_4 = { 7716 720a 817c242000f00700 730a 8b442420 894c243c }
            // n = 6, score = 100
            //   7716                 | ja                  0x18
            //   720a                 | jb                  0xc
            //   817c242000f00700     | cmp                 dword ptr [esp + 0x20], 0x7f000
            //   730a                 | jae                 0xc
            //   8b442420             | mov                 eax, dword ptr [esp + 0x20]
            //   894c243c             | mov                 dword ptr [esp + 0x3c], ecx

        $sequence_5 = { c7873001000001000000 6a00 6a02 68???????? ff75fc ffd6 5f }
            // n = 7, score = 100
            //   c7873001000001000000     | mov    dword ptr [edi + 0x130], 1
            //   6a00                 | push                0
            //   6a02                 | push                2
            //   68????????           |                     
            //   ff75fc               | push                dword ptr [ebp - 4]
            //   ffd6                 | call                esi
            //   5f                   | pop                 edi

        $sequence_6 = { eb05 ff7240 33c0 e8???????? 8bf0 59 85f6 }
            // n = 7, score = 100
            //   eb05                 | jmp                 7
            //   ff7240               | push                dword ptr [edx + 0x40]
            //   33c0                 | xor                 eax, eax
            //   e8????????           |                     
            //   8bf0                 | mov                 esi, eax
            //   59                   | pop                 ecx
            //   85f6                 | test                esi, esi

        $sequence_7 = { 8d856bdfffff e8???????? 59 8945e4 85c0 740b 50 }
            // n = 7, score = 100
            //   8d856bdfffff         | lea                 eax, [ebp - 0x2095]
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   8945e4               | mov                 dword ptr [ebp - 0x1c], eax
            //   85c0                 | test                eax, eax
            //   740b                 | je                  0xd
            //   50                   | push                eax

        $sequence_8 = { ff15???????? 89442410 3bc3 750d c744240808000000 e9???????? 53 }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   89442410             | mov                 dword ptr [esp + 0x10], eax
            //   3bc3                 | cmp                 eax, ebx
            //   750d                 | jne                 0xf
            //   c744240808000000     | mov                 dword ptr [esp + 8], 8
            //   e9????????           |                     
            //   53                   | push                ebx

        $sequence_9 = { 68c0270900 ffb744010000 ff15???????? 8364240c00 6a00 ffb744010000 ff15???????? }
            // n = 7, score = 100
            //   68c0270900           | push                0x927c0
            //   ffb744010000         | push                dword ptr [edi + 0x144]
            //   ff15????????         |                     
            //   8364240c00           | and                 dword ptr [esp + 0xc], 0
            //   6a00                 | push                0
            //   ffb744010000         | push                dword ptr [edi + 0x144]
            //   ff15????????         |                     

    condition:
        7 of them and filesize < 156672
}
Download all Yara Rules