SYMBOLCOMMON_NAMEaka. SYNONYMS
win.bistromath (Back to overview)

BISTROMATH

Actor(s): Lazarus Group, Silent Chollima

VTCollection    

There is no description at this point.

References
2021-06-15 ⋅ Kaspersky ⋅ Seongsu Park
Andariel evolves to target South Korea with ransomware
BISTROMATH PEBBLEDASH SHATTEREDGLASS TigerLite Tiger RAT
2021-05-11 ⋅ ⋅ Qianxin ⋅ Red Raindrop Team
Analysis of a series of attacks by the suspected Lazarus organization using Daewoo Shipyard as relevant bait
BISTROMATH TigerLite
2021-04-19 ⋅ Malwarebytes ⋅ Hossein Jazi
Lazarus APT conceals malicious code within BMP image to drop its RAT
BISTROMATH
2020-02-25 ⋅ SentinelOne ⋅ Jim Walter
DPRK Hidden Cobra Update: North Korean Malicious Cyber Activity
ARTFULPIE BISTROMATH BUFFETLINE CHEESETRAY HOPLIGHT HOTCROISSANT SLICKSHOES
2020-02-14 ⋅ US-CERT ⋅ US-CERT
Malware Analysis Report (AR20-045A): MAR-10265965-1.v1 - North Korean Trojan: BISTROMATH
BISTROMATH
Yara Rules
[TLP:WHITE] win_bistromath_auto (20260917 | Detects win.bistromath.)
rule win_bistromath_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.bistromath."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bistromath"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ffd3 8b5724 83c410 8b0f e8???????? 0f10442418 8b442450 }
            // n = 7, score = 400
            //   ffd3                 | call                ebx
            //   8b5724               | mov                 edx, dword ptr [edi + 0x24]
            //   83c410               | add                 esp, 0x10
            //   8b0f                 | mov                 ecx, dword ptr [edi]
            //   e8????????           |                     
            //   0f10442418           | movups              xmm0, xmmword ptr [esp + 0x18]
            //   8b442450             | mov                 eax, dword ptr [esp + 0x50]

        $sequence_1 = { e8???????? 6a00 57 ba38000000 e8???????? 83c438 8b7c2428 }
            // n = 7, score = 400
            //   e8????????           |                     
            //   6a00                 | push                0
            //   57                   | push                edi
            //   ba38000000           | mov                 edx, 0x38
            //   e8????????           |                     
            //   83c438               | add                 esp, 0x38
            //   8b7c2428             | mov                 edi, dword ptr [esp + 0x28]

        $sequence_2 = { c78530ffffff65007400 c78534ffffff43006f00 c78538ffffff6f006b00 c7853cffffff69006500 c78540ffffff73005c00 c78544ffffff4c006f00 c78548ffffff77000000 }
            // n = 7, score = 400
            //   c78530ffffff65007400     | mov    dword ptr [ebp - 0xd0], 0x740065
            //   c78534ffffff43006f00     | mov    dword ptr [ebp - 0xcc], 0x6f0043
            //   c78538ffffff6f006b00     | mov    dword ptr [ebp - 0xc8], 0x6b006f
            //   c7853cffffff69006500     | mov    dword ptr [ebp - 0xc4], 0x650069
            //   c78540ffffff73005c00     | mov    dword ptr [ebp - 0xc0], 0x5c0073
            //   c78544ffffff4c006f00     | mov    dword ptr [ebp - 0xbc], 0x6f004c
            //   c78548ffffff77000000     | mov    dword ptr [ebp - 0xb8], 0x77

        $sequence_3 = { c7411000000000 8801 8b44242c 894104 c6410100 8b742418 8b442420 }
            // n = 7, score = 400
            //   c7411000000000       | mov                 dword ptr [ecx + 0x10], 0
            //   8801                 | mov                 byte ptr [ecx], al
            //   8b44242c             | mov                 eax, dword ptr [esp + 0x2c]
            //   894104               | mov                 dword ptr [ecx + 4], eax
            //   c6410100             | mov                 byte ptr [ecx + 1], 0
            //   8b742418             | mov                 esi, dword ptr [esp + 0x18]
            //   8b442420             | mov                 eax, dword ptr [esp + 0x20]

        $sequence_4 = { 8bd7 e8???????? 8b7dbc 8d4301 57 50 ba17000000 }
            // n = 7, score = 400
            //   8bd7                 | mov                 edx, edi
            //   e8????????           |                     
            //   8b7dbc               | mov                 edi, dword ptr [ebp - 0x44]
            //   8d4301               | lea                 eax, [ebx + 1]
            //   57                   | push                edi
            //   50                   | push                eax
            //   ba17000000           | mov                 edx, 0x17

        $sequence_5 = { c3 55 8bec 81ec040a0000 a1???????? 33c5 8945fc }
            // n = 7, score = 400
            //   c3                   | ret                 
            //   55                   | push                ebp
            //   8bec                 | mov                 ebp, esp
            //   81ec040a0000         | sub                 esp, 0xa04
            //   a1????????           |                     
            //   33c5                 | xor                 eax, ebp
            //   8945fc               | mov                 dword ptr [ebp - 4], eax

        $sequence_6 = { eb1c 8b8564ffffff eb11 8b8d60ffffff 8bd6 53 e8???????? }
            // n = 7, score = 400
            //   eb1c                 | jmp                 0x1e
            //   8b8564ffffff         | mov                 eax, dword ptr [ebp - 0x9c]
            //   eb11                 | jmp                 0x13
            //   8b8d60ffffff         | mov                 ecx, dword ptr [ebp - 0xa0]
            //   8bd6                 | mov                 edx, esi
            //   53                   | push                ebx
            //   e8????????           |                     

        $sequence_7 = { c78518ffffff7b003300 c7851cffffff43004300 c78520ffffff44003500 c78524ffffff34003900 c78528ffffff39002d00 c7852cffffff38003700 c78530ffffff41003800 }
            // n = 7, score = 400
            //   c78518ffffff7b003300     | mov    dword ptr [ebp - 0xe8], 0x33007b
            //   c7851cffffff43004300     | mov    dword ptr [ebp - 0xe4], 0x430043
            //   c78520ffffff44003500     | mov    dword ptr [ebp - 0xe0], 0x350044
            //   c78524ffffff34003900     | mov    dword ptr [ebp - 0xdc], 0x390034
            //   c78528ffffff39002d00     | mov    dword ptr [ebp - 0xd8], 0x2d0039
            //   c7852cffffff38003700     | mov    dword ptr [ebp - 0xd4], 0x370038
            //   c78530ffffff41003800     | mov    dword ptr [ebp - 0xd0], 0x380041

        $sequence_8 = { e8???????? 85f6 0f4475d0 eb03 8b7dc4 8b55d4 8b45bc }
            // n = 7, score = 400
            //   e8????????           |                     
            //   85f6                 | test                esi, esi
            //   0f4475d0             | cmove               esi, dword ptr [ebp - 0x30]
            //   eb03                 | jmp                 5
            //   8b7dc4               | mov                 edi, dword ptr [ebp - 0x3c]
            //   8b55d4               | mov                 edx, dword ptr [ebp - 0x2c]
            //   8b45bc               | mov                 eax, dword ptr [ebp - 0x44]

        $sequence_9 = { eb03 8b4510 46 3b750c 7cca 8b55fc 8b4d08 }
            // n = 7, score = 400
            //   eb03                 | jmp                 5
            //   8b4510               | mov                 eax, dword ptr [ebp + 0x10]
            //   46                   | inc                 esi
            //   3b750c               | cmp                 esi, dword ptr [ebp + 0xc]
            //   7cca                 | jl                  0xffffffcc
            //   8b55fc               | mov                 edx, dword ptr [ebp - 4]
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]

    condition:
        7 of them and filesize < 33816576
}
Download all Yara Rules