SYMBOLCOMMON_NAMEaka. SYNONYMS
win.billgates (Back to overview)

BillGates

VTCollection    

BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules.

BillGates is available for *nix-based systems as well as for Windows.

On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.

References
2022-03-02 ⋅ Bleeping Computer ⋅ Bill Toulas
Log4shell exploits now used mostly for DDoS botnets, cryptominers
Kinsing Tsunami BillGates
2021-10-22 ⋅ Fortinet ⋅ Cara Lin
Recent Attack Uses Vulnerability on Confluence Server
Tsunami BillGates
2017-12-03 ⋅ Blaze's Security Blog ⋅ BartBlaze
Notes on Linux/BillGates
BillGates
2016-04-04 ⋅ Akamai ⋅ Akamai
Threat Advisory: “BillGates” Botnet
BillGates
2015-09-30 ⋅ ThisIsSecurity ⋅ Benoît Ancel
When ELF.BillGates met Windows
BillGates
2015-09-01 ⋅ Virus Bulletin ⋅ Jaromír Hořejší, Peter Kálnai
DDOS TROJAN: A MALICIOUS CONCEPT THAT CONQUERED THE ELF FORMAT
Bashlite MrBlack XOR DDoS BillGates
2014-07-10 ⋅ Kaspersky Labs ⋅ Mikhail Kuzin
Versatile DDoS Trojan for Linux
BillGates
2014-02-06 ⋅ ⋅ Habr ⋅ ValdikSS
Исследуем Linux Botnet «BillGates»
BillGates
Yara Rules
[TLP:WHITE] win_billgates_auto (20260917 | Detects win.billgates.)
rule win_billgates_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.billgates."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.billgates"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8d8809f9ffff b8c94216b2 f7e9 03d1 }
            // n = 4, score = 200
            //   8d8809f9ffff         | mov                 ebp, dword ptr [esi + 0x20]
            //   b8c94216b2           | cmp                 ebp, 1
            //   f7e9                 | mov                 dword ptr [esi + 0x1c], ebx
            //   03d1                 | mov                 dword ptr [esi + 0x24], ebx

        $sequence_1 = { 7408 3c23 7404 3c24 }
            // n = 4, score = 200
            //   7408                 | cmp                 al, 0x30
            //   3c23                 | jne                 0x1a3c
            //   7404                 | push                edi
            //   3c24                 | xor                 edi, edi

        $sequence_2 = { 3c11 7408 3c22 7404 3c30 }
            // n = 5, score = 200
            //   3c11                 | mov                 eax, dword ptr [esp + 0x50]
            //   7408                 | dec                 eax
            //   3c22                 | and                 dword ptr [esp + 0x20], 0
            //   7404                 | dec                 eax
            //   3c30                 | lea                 ecx, [0x2823b]

        $sequence_3 = { 7408 3c22 7404 3c30 }
            // n = 4, score = 200
            //   7408                 | xor                 esi, esi
            //   3c22                 | cmp                 dword ptr [esi*8 + 0x4401c4], 1
            //   7404                 | push                edi
            //   3c30                 | xor                 edi, edi

        $sequence_4 = { 3c58 7507 b802000000 eb02 }
            // n = 4, score = 200
            //   3c58                 | call                ebp
            //   7507                 | cmp                 edi, eax
            //   b802000000           | je                  0x63
            //   eb02                 | mov                 ecx, eax

        $sequence_5 = { 3c22 7404 3c30 7504 }
            // n = 4, score = 200
            //   3c22                 | cmp                 dword ptr [esi + 0xc], eax
            //   7404                 | cmp                 esi, ebx
            //   3c30                 | je                  0x48b
            //   7504                 | sub                 ebp, esi

        $sequence_6 = { 3c21 7408 3c23 7404 }
            // n = 4, score = 200
            //   3c21                 | push                4
            //   7408                 | cmp                 esi, ebx
            //   3c23                 | je                  0x477
            //   7404                 | mov                 eax, dword ptr [esp + 0x24]

        $sequence_7 = { 3c10 740c 3c11 7408 3c22 }
            // n = 5, score = 200
            //   3c10                 | mov                 ebx, dword ptr [ebp + 0xc]
            //   740c                 | mov                 ecx, edi
            //   3c11                 | sub                 ecx, ebx
            //   7408                 | je                  0x441
            //   3c22                 | dec                 eax

        $sequence_8 = { 740c 3c11 7408 3c22 7404 3c30 }
            // n = 6, score = 200
            //   740c                 | dec                 eax
            //   3c11                 | lea                 edx, [esp + 0x20]
            //   7408                 | dec                 eax
            //   3c22                 | lea                 edx, [esp + 0x20]
            //   7404                 | dec                 eax
            //   3c30                 | lea                 ecx, [esi + 0x1c]

        $sequence_9 = { 3c10 740c 3c11 7408 }
            // n = 4, score = 200
            //   3c10                 | je                  0x547
            //   740c                 | cmp                 dword ptr [esi + 4], ebx
            //   3c11                 | cmp                 esi, ebx
            //   7408                 | je                  0x4de

    condition:
        7 of them and filesize < 801792
}
Download all Yara Rules