Ransomware
rule win_blackmagic_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.blackmagic." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.blackmagic" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 488d4d07 e8???????? 488bd8 498d4e08 488d159bd50900 e8???????? 4c8bc0 } // n = 7, score = 100 // 488d4d07 | dec esp // e8???????? | // 488bd8 | mov ecx, dword ptr [ebp - 0x69] // 498d4e08 | dec eax // 488d159bd50900 | test edx, edx // e8???????? | // 4c8bc0 | je 0x6ba $sequence_1 = { 663928 741d 4c8d0d9a3b0200 4889442420 41b802000000 488bd7 488bce } // n = 7, score = 100 // 663928 | dec eax // 741d | xor ecx, esp // 4c8d0d9a3b0200 | dec esp // 4889442420 | lea ebx, [esp + 0x1d0] // 41b802000000 | dec ecx // 488bd7 | mov ebx, dword ptr [ebx + 0x18] // 488bce | dec ecx $sequence_2 = { 85c0 7421 4585e4 740e 8bc7 2500070000 } // n = 6, score = 100 // 85c0 | mov dword ptr [esp + 0x38], eax // 7421 | dec eax // 4585e4 | lea edx, [0x9345f] // 740e | dec eax // 8bc7 | lea ecx, [esp + 0x38] // 2500070000 | int3 $sequence_3 = { e8???????? cc e8???????? 488bd0 488d4dd7 e8???????? } // n = 6, score = 100 // e8???????? | // cc | dec eax // e8???????? | // 488bd0 | lea ecx, [ebp + 0x138] // 488d4dd7 | nop // e8???????? | $sequence_4 = { 48ffc3 80380a 753a 483bd9 7435 0fb60b 80f920 } // n = 7, score = 100 // 48ffc3 | dec eax // 80380a | mov dword ptr [eax + 0x10], ebp // 753a | dec eax // 483bd9 | lea eax, [0x67283] // 7435 | dec eax // 0fb60b | mov dword ptr [ebx], eax // 80f920 | dec eax $sequence_5 = { 8079010a 7514 48ffc1 eb0f 0fb601 4a0fbe842840bb0900 4803c8 } // n = 7, score = 100 // 8079010a | dec eax // 7514 | lea eax, [0x4a3a6] // 48ffc1 | dec eax // eb0f | mov dword ptr [esp + 0x40], eax // 0fb601 | dec eax // 4a0fbe842840bb0900 | lea eax, [0x4a502] // 4803c8 | dec eax $sequence_6 = { 4c8b0d???????? 488b9780000000 488b01 ff5030 4533ff 488d05e8560400 488d4c2430 } // n = 7, score = 100 // 4c8b0d???????? | // 488b9780000000 | dec ebp // 488b01 | mov esi, ecx // ff5030 | dec eax // 4533ff | mov ecx, dword ptr [ecx] // 488d05e8560400 | inc ecx // 488d4c2430 | mov ebp, eax $sequence_7 = { 4883ec78 488b05???????? 4833c4 488945e8 4c8b4118 488bd9 493bd0 } // n = 7, score = 100 // 4883ec78 | mov edx, eax // 488b05???????? | // 4833c4 | dec eax // 488945e8 | lea ecx, [ebp + 0x10] // 4c8b4118 | nop // 488bd9 | dec esp // 493bd0 | lea eax, [0x7ebed] $sequence_8 = { 4c3bf0 7413 4983c9ff 4533c0 488d55f7 498bce e8???????? } // n = 7, score = 100 // 4c3bf0 | dec eax // 7413 | mov dword ptr [ebx + 0x18], edi // 4983c9ff | mov esi, 4 // 4533c0 | dec eax // 488d55f7 | mov edx, dword ptr [esp + 0x28] // 498bce | dec eax // e8???????? | $sequence_9 = { 3b5128 0f84a1000000 48c74424400f000000 48c744243800000000 c644242800 41b846000000 488d15bbdf0700 } // n = 7, score = 100 // 3b5128 | mov byte ptr [ebp + 0x38], 0 // 0f84a1000000 | dec eax // 48c74424400f000000 | lea edx, [ebp + 0x168] // 48c744243800000000 | dec eax // c644242800 | lea ecx, [ebp + 0x38] // 41b846000000 | jne 0x4ac // 488d15bbdf0700 | cmp eax, 0x2733 condition: 7 of them and filesize < 1416192 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY