SYMBOLCOMMON_NAMEaka. SYNONYMS
win.cryptowall (Back to overview)

Cryptowall

VTCollection    

CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.

References
2020-11-23 ⋅ Medium ryancor ⋅ Ryan Cornateanu
Genetic Analysis of CryptoWall Ransomware
Cryptowall
2020-08-01 ⋅ Temple University ⋅ CARE
Critical Infrastructure Ransomware Attacks
CryptoLocker Cryptowall DoppelPaymer FriedEx Mailto Maze REvil Ryuk SamSam WannaCryptor
2020-07-29 ⋅ ESET Research ⋅ welivesecurity
THREAT REPORT Q2 2020
DEFENSOR ID HiddenAd Bundlore Pirrit Agent.BTZ Cerber ClipBanker CROSSWALK Cryptowall CTB Locker DanaBot Dharma Formbook Gandcrab Grandoreiro Houdini ISFB LockBit Locky Mailto Maze Microcin Nemty NjRAT Phobos PlugX Pony REvil Socelars STOP Tinba TrickBot WannaCryptor
2019-06-12 ⋅ Gdata ⋅ Karsten Hahn
Ransomware identification for the judicious analyst
Cerber Cryptowall CryptoFortress Locky PadCrypt Spora VirLock
Yara Rules
[TLP:WHITE] win_cryptowall_auto (20260917 | Detects win.cryptowall.)
rule win_cryptowall_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.cryptowall."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptowall"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8d540902 52 8b450c 50 8b4d08 51 e8???????? }
            // n = 7, score = 2100
            //   8d540902             | lea                 edx, [ecx + ecx + 2]
            //   52                   | push                edx
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   50                   | push                eax
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]
            //   51                   | push                ecx
            //   e8????????           |                     

        $sequence_1 = { 51 6a00 e8???????? 8b5018 52 }
            // n = 5, score = 2100
            //   51                   | push                ecx
            //   6a00                 | push                0
            //   e8????????           |                     
            //   8b5018               | mov                 edx, dword ptr [eax + 0x18]
            //   52                   | push                edx

        $sequence_2 = { 8bec 51 8b450c 83e801 234508 7418 }
            // n = 6, score = 2100
            //   8bec                 | mov                 ebp, esp
            //   51                   | push                ecx
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   83e801               | sub                 eax, 1
            //   234508               | and                 eax, dword ptr [ebp + 8]
            //   7418                 | je                  0x1a

        $sequence_3 = { 8b4508 8b4cd004 51 e8???????? 83c404 ebda }
            // n = 6, score = 2100
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   8b4cd004             | mov                 ecx, dword ptr [eax + edx*8 + 4]
            //   51                   | push                ecx
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   ebda                 | jmp                 0xffffffdc

        $sequence_4 = { 8b4514 50 8b4d10 83c101 51 8b550c }
            // n = 6, score = 2100
            //   8b4514               | mov                 eax, dword ptr [ebp + 0x14]
            //   50                   | push                eax
            //   8b4d10               | mov                 ecx, dword ptr [ebp + 0x10]
            //   83c101               | add                 ecx, 1
            //   51                   | push                ecx
            //   8b550c               | mov                 edx, dword ptr [ebp + 0xc]

        $sequence_5 = { 7502 eb09 b801000000 85c0 759f }
            // n = 5, score = 2100
            //   7502                 | jne                 4
            //   eb09                 | jmp                 0xb
            //   b801000000           | mov                 eax, 1
            //   85c0                 | test                eax, eax
            //   759f                 | jne                 0xffffffa1

        $sequence_6 = { ffd2 8b4514 50 8b4d10 51 8b5518 52 }
            // n = 7, score = 2100
            //   ffd2                 | call                edx
            //   8b4514               | mov                 eax, dword ptr [ebp + 0x14]
            //   50                   | push                eax
            //   8b4d10               | mov                 ecx, dword ptr [ebp + 0x10]
            //   51                   | push                ecx
            //   8b5518               | mov                 edx, dword ptr [ebp + 0x18]
            //   52                   | push                edx

        $sequence_7 = { 8b483c 51 e8???????? 83c408 3b4508 751c }
            // n = 6, score = 2100
            //   8b483c               | mov                 ecx, dword ptr [eax + 0x3c]
            //   51                   | push                ecx
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   3b4508               | cmp                 eax, dword ptr [ebp + 8]
            //   751c                 | jne                 0x1e

        $sequence_8 = { e8???????? 83c408 e9???????? 837d0c02 752e }
            // n = 5, score = 2100
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   e9????????           |                     
            //   837d0c02             | cmp                 dword ptr [ebp + 0xc], 2
            //   752e                 | jne                 0x30

        $sequence_9 = { e8???????? 8b10 ffd2 8b45f8 }
            // n = 4, score = 2100
            //   e8????????           |                     
            //   8b10                 | mov                 edx, dword ptr [eax]
            //   ffd2                 | call                edx
            //   8b45f8               | mov                 eax, dword ptr [ebp - 8]

    condition:
        7 of them and filesize < 417792
}
Download all Yara Rules