SYMBOLCOMMON_NAMEaka. SYNONYMS
win.contopee (Back to overview)

Contopee

aka: WHITEOUT

Actor(s): Lazarus Group

VTCollection    

FireEye described this malware as a proxy-aware backdoor that communicates using a custom-encrypted binary protocol. It may use the registry to store optional configuration data. The backdoor has been observed to support 26 commands that include directory traversal, file system manipulation, data archival and transmission, and command execution.

References
2018-01-01 ⋅ FireEye ⋅ FireEye
APT38
Bitsran BLINDTOAD BOOTWRECK Contopee DarkComet DYEPACK HOTWAX NESTEGG PowerRatankba REDSHAWL WORMHOLE Lazarus Group
2016-05-26 ⋅ Symantec ⋅ Symantec Security Response
SWIFT attackers’ malware linked to more financial attacks
Contopee Lazarus Group
2016-05-26 ⋅ Symantec ⋅ Security Response
SWIFT attackers’ malware linked to more financial attacks
Contopee DYEPACK Sierra(Alfa,Bravo, ...) Lazarus Group
Yara Rules
[TLP:WHITE] win_contopee_auto (20260917 | Detects win.contopee.)
rule win_contopee_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.contopee."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.contopee"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 81c404010000 c3 81ec04010000 53 56 8bb42418010000 57 }
            // n = 7, score = 100
            //   81c404010000         | add                 esp, 0x104
            //   c3                   | ret                 
            //   81ec04010000         | sub                 esp, 0x104
            //   53                   | push                ebx
            //   56                   | push                esi
            //   8bb42418010000       | mov                 esi, dword ptr [esp + 0x118]
            //   57                   | push                edi

        $sequence_1 = { 8d4c2434 57 51 ffd3 83c408 85c0 }
            // n = 6, score = 100
            //   8d4c2434             | lea                 ecx, [esp + 0x34]
            //   57                   | push                edi
            //   51                   | push                ecx
            //   ffd3                 | call                ebx
            //   83c408               | add                 esp, 8
            //   85c0                 | test                eax, eax

        $sequence_2 = { 85db 0f8486000000 6804010000 55 6a00 53 ff15???????? }
            // n = 7, score = 100
            //   85db                 | test                ebx, ebx
            //   0f8486000000         | je                  0x8c
            //   6804010000           | push                0x104
            //   55                   | push                ebp
            //   6a00                 | push                0
            //   53                   | push                ebx
            //   ff15????????         |                     

        $sequence_3 = { 50 ffd5 83c410 8d4c2410 8d942460020000 51 52 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   ffd5                 | call                ebp
            //   83c410               | add                 esp, 0x10
            //   8d4c2410             | lea                 ecx, [esp + 0x10]
            //   8d942460020000       | lea                 edx, [esp + 0x260]
            //   51                   | push                ecx
            //   52                   | push                edx

        $sequence_4 = { 8d0480 6a00 8d0c80 8a842428010000 c1e103 84c0 894c2410 }
            // n = 7, score = 100
            //   8d0480               | lea                 eax, [eax + eax*4]
            //   6a00                 | push                0
            //   8d0c80               | lea                 ecx, [eax + eax*4]
            //   8a842428010000       | mov                 al, byte ptr [esp + 0x128]
            //   c1e103               | shl                 ecx, 3
            //   84c0                 | test                al, al
            //   894c2410             | mov                 dword ptr [esp + 0x10], ecx

        $sequence_5 = { 56 68???????? 6a00 894e18 895e20 6a00 897e14 }
            // n = 7, score = 100
            //   56                   | push                esi
            //   68????????           |                     
            //   6a00                 | push                0
            //   894e18               | mov                 dword ptr [esi + 0x18], ecx
            //   895e20               | mov                 dword ptr [esi + 0x20], ebx
            //   6a00                 | push                0
            //   897e14               | mov                 dword ptr [esi + 0x14], edi

        $sequence_6 = { 33d2 8ad5 894c2418 8a44241a 83c604 8b1c9530f20010 8bd1 }
            // n = 7, score = 100
            //   33d2                 | xor                 edx, edx
            //   8ad5                 | mov                 dl, ch
            //   894c2418             | mov                 dword ptr [esp + 0x18], ecx
            //   8a44241a             | mov                 al, byte ptr [esp + 0x1a]
            //   83c604               | add                 esi, 4
            //   8b1c9530f20010       | mov                 ebx, dword ptr [edx*4 + 0x1000f230]
            //   8bd1                 | mov                 edx, ecx

        $sequence_7 = { ffd7 83c418 8d8c2450020000 6804010000 }
            // n = 4, score = 100
            //   ffd7                 | call                edi
            //   83c418               | add                 esp, 0x18
            //   8d8c2450020000       | lea                 ecx, [esp + 0x250]
            //   6804010000           | push                0x104

        $sequence_8 = { 81c590030000 f3a4 8dbb54020000 83c9ff f2ae }
            // n = 5, score = 100
            //   81c590030000         | add                 ebp, 0x390
            //   f3a4                 | rep movsb           byte ptr es:[edi], byte ptr [esi]
            //   8dbb54020000         | lea                 edi, [ebx + 0x254]
            //   83c9ff               | or                  ecx, 0xffffffff
            //   f2ae                 | repne scasb         al, byte ptr es:[edi]

        $sequence_9 = { 52 8b16 8d4c242c 50 51 52 }
            // n = 6, score = 100
            //   52                   | push                edx
            //   8b16                 | mov                 edx, dword ptr [esi]
            //   8d4c242c             | lea                 ecx, [esp + 0x2c]
            //   50                   | push                eax
            //   51                   | push                ecx
            //   52                   | push                edx

    condition:
        7 of them and filesize < 180224
}
Download all Yara Rules