There is no description at this point.
rule win_cicada3301_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.cicada3301." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cicada3301" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { e8???????? 8b4c2428 8b44242c 83f902 7574 49be0000000002000000 4c09f0 } // n = 7, score = 100 // e8???????? | // 8b4c2428 | je 0x221 // 8b44242c | dec eax // 83f902 | mov ecx, dword ptr [ebp + 0x1e8] // 7574 | cmp dword ptr [ebp + 0xffc], 0 // 49be0000000002000000 | je 0x203 // 4c09f0 | mov ecx, dword ptr [ebp + 0x1000] $sequence_1 = { f30f104008 0f14c4 f30f10600c 0f14e5 410f58e1 0f59e2 0f58e0 } // n = 7, score = 100 // f30f104008 | mulsd xmm1, xmm0 // 0f14c4 | subsd xmm4, xmm2 // f30f10600c | subsd xmm4, xmm3 // 0f14e5 | subsd xmm1, xmm4 // 410f58e1 | movapd xmm3, xmm2 // 0f59e2 | subsd xmm3, xmm1 // 0f58e0 | mulsd xmm1, xmm1 $sequence_2 = { eb1d 4889c1 48d1e9 83e001 4809c8 f3480f2ac0 f30f58c0 } // n = 7, score = 100 // eb1d | inc ebp // 4889c1 | xor edi, edi // 48d1e9 | dec esp // 83e001 | mov dword ptr [esp + 0xd8], edi // 4809c8 | dec eax // f3480f2ac0 | mov dword ptr [esp + 0x78], ebx // f30f58c0 | dec esp $sequence_3 = { e9???????? 488b542428 4889d1 4d89f8 ebc3 4c8d0507c33a00 eb07 } // n = 7, score = 100 // e9???????? | // 488b542428 | lea edx, [eax + eax*2] // 4889d1 | jmp 0x6c // 4d89f8 | dec eax // ebc3 | mov eax, dword ptr [edi] // 4c8d0507c33a00 | dec eax // eb07 | test eax, eax $sequence_4 = { e8???????? a801 7526 c1e810 48897dd0 4c8975d8 668945e0 } // n = 7, score = 100 // e8???????? | // a801 | dec eax // 7526 | mov ecx, dword ptr [edi + 0x180] // c1e810 | dec eax // 48897dd0 | imul eax, dword ptr [edi + 0x188], 0x258 // 4c8975d8 | test al, al // 668945e0 | dec eax $sequence_5 = { e9???????? 418b8598010000 85c0 0f8485000000 41398594010000 0f828d000000 4c8b5e20 } // n = 7, score = 100 // e9???????? | // 418b8598010000 | lea eax, [0x2c0002] // 85c0 | dec eax // 0f8485000000 | mov ecx, ebp // 41398594010000 | dec eax // 0f828d000000 | mov edx, ebx // 4c8b5e20 | dec esp $sequence_6 = { e8???????? 4885c0 7405 4883c428 c3 b908000000 ba401b0000 } // n = 7, score = 100 // e8???????? | // 4885c0 | mov dword ptr [eax], 0x626d7564 // 7405 | dec esp // 4883c428 | cmp edi, edi // c3 | jne 0x8ad // b908000000 | mov edx, 4 // ba401b0000 | dec eax $sequence_7 = { e9???????? 41bb01000000 4531c9 be01000000 4531c0 4983fa05 0f830cffffff } // n = 7, score = 100 // e9???????? | // 41bb01000000 | dec esp // 4531c9 | lea eax, [0x29377a] // be01000000 | dec eax // 4531c0 | lea ecx, [esp + 0xd8] // 4983fa05 | inc ecx // 0f830cffffff | mov ecx, 0xe $sequence_8 = { 80beca01000000 745c 448d59bf 4180fb1a 7308 80c920 4189cb } // n = 7, score = 100 // 80beca01000000 | dec eax // 745c | cmp eax, 3 // 448d59bf | je 0x949 // 4180fb1a | or byte ptr [edi + ebx + 0x80], 0x40 // 7308 | or byte ptr [edi + ebx + 0x90], 0x40 // 80c920 | inc ecx // 4189cb | shr esi, 4 $sequence_9 = { f20f59c2 58 c3 f20f5805???????? f20f100d???????? b8ffffffff 660f28d0 } // n = 7, score = 100 // f20f59c2 | test eax, eax // 58 | je 0x253 // c3 | dec eax // f20f5805???????? | // f20f100d???????? | // b8ffffffff | shl eax, 4 // 660f28d0 | dec eax condition: 7 of them and filesize < 11247616 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY