Actor(s): Lazarus Group
Potential Lazarus sample.
rule win_cur1_downloader_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.cur1_downloader." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.cur1_downloader" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { ff15???????? 3db7000000 750a c744242401000000 eb08 c744242400000000 } // n = 6, score = 100 // ff15???????? | // 3db7000000 | mov byte ptr [esp + 0x47], 0x35 // 750a | mov byte ptr [esp + 0x42], 0x61 // c744242401000000 | mov byte ptr [esp + 0x43], 0x70 // eb08 | mov byte ptr [esp + 0x44], 0x69 // c744242400000000 | mov byte ptr [esp + 0x45], 0x2e $sequence_1 = { 4889442428 488b842490000000 4889442458 488b442458 4889442438 488b442458 4883c008 } // n = 7, score = 100 // 4889442428 | and edx, 0x3f // 488b842490000000 | dec eax // 4889442458 | mov ecx, edi // 488b442458 | dec eax // 4889442438 | sar ecx, 6 // 488b442458 | dec eax // 4883c008 | lea eax, [0x16104] $sequence_2 = { 7419 488b4c2448 e8???????? 488bd0 488b4c2440 e8???????? eb1f } // n = 7, score = 100 // 7419 | dec eax // 488b4c2448 | lea eax, [0x13a8e] // e8???????? | // 488bd0 | dec eax // 488b4c2440 | cmp dword ptr [edi - 0x10], eax // e8???????? | // eb1f | dec eax $sequence_3 = { 488d0ddf5a0100 e8???????? c705????????02000000 4032ff 8acb e8???????? 4084ff } // n = 7, score = 100 // 488d0ddf5a0100 | lea eax, [0x12c61] // e8???????? | // c705????????02000000 | // 4032ff | dec eax // 8acb | lea edx, [0x12c62] // e8???????? | // 4084ff | inc eax $sequence_4 = { ff15???????? 90 488d8c2498000000 e8???????? e9???????? 488d8c2498000000 } // n = 6, score = 100 // ff15???????? | // 90 | mov byte ptr [esp + 0x1a2], 0x65 // 488d8c2498000000 | mov byte ptr [esp + 0x1a3], 0x61 // e8???????? | // e9???????? | // 488d8c2498000000 | mov byte ptr [esp + 0x1a4], 0x74 $sequence_5 = { c68424880100006c c68424890100006c c684248a0100006f c684248b01000063 c684248c01000045 c684248d01000078 c684248e01000000 } // n = 7, score = 100 // c68424880100006c | dec esp // c68424890100006c | lea ecx, [0xb1c4] // c684248a0100006f | subsd xmm1, xmm2 // c684248b01000063 | inc ecx // c684248c01000045 | mulps xmm1, xmmword ptr [ecx + eax*8] // c684248d01000078 | movapd xmm2, xmm1 // c684248e01000000 | movapd xmm0, xmm1 $sequence_6 = { 41b804010000 488d942400030000 33c9 ff15???????? c744245801000000 e8???????? 833d????????01 } // n = 7, score = 100 // 41b804010000 | mov byte ptr [esp + 0x195], 0x65 // 488d942400030000 | mov byte ptr [esp + 0x196], 0x50 // 33c9 | mov byte ptr [esp + 0x197], 0x72 // ff15???????? | // c744245801000000 | mov byte ptr [esp + 0x198], 0x6f // e8???????? | // 833d????????01 | $sequence_7 = { 88442420 48837c242800 7409 0fb6442420 85c0 } // n = 5, score = 100 // 88442420 | test eax, eax // 48837c242800 | dec eax // 7409 | lea ecx, [0xffffcd04] // 0fb6442420 | test eax, eax // 85c0 | jne 0x7e6 $sequence_8 = { 48895108 41f6c101 7427 0fb60a 83e10f 4a0fbe841900e40100 } // n = 6, score = 100 // 48895108 | nop // 41f6c101 | dec eax // 7427 | lea eax, [0x21c8a] // 0fb60a | dec eax // 83e10f | mov dword ptr [esp + 0x28], eax // 4a0fbe841900e40100 | movzx edx, byte ptr [esp + 0x30] $sequence_9 = { 488d0de1600100 0f57c0 48890b 488d5308 488d4808 0f1102 } // n = 6, score = 100 // 488d0de1600100 | lea edx, [esp + 0x1720] // 0f57c0 | xor ecx, ecx // 48890b | mov dword ptr [esp + 0x68], eax // 488d5308 | inc ebp // 488d4808 | xor ecx, ecx // 0f1102 | inc ebp condition: 7 of them and filesize < 402432 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY