A RAT written in .NET, used by FIN7 since 2021. In some instances dropped by ps1.powertrash.
rule win_diceloader_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.diceloader." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.diceloader" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 834c2420ff 4c8d442450 488d542448 ff15???????? } // n = 4, score = 100 // 834c2420ff | dec eax // 4c8d442450 | lea ecx, [0x2a12] // 488d542448 | dec eax // ff15???????? | $sequence_1 = { 498d043c 4883c448 415f 415e 415d } // n = 5, score = 100 // 498d043c | dec esp // 4883c448 | mov dword ptr [esp + 0x28], edi // 415f | dec esp // 415e | lea eax, [0x91] // 415d | xor ebx, ebx $sequence_2 = { 4d85e4 7514 4d8b1b 4c899c24a0000000 4d85db 0f8539feffff 4c8bbc2498000000 } // n = 7, score = 100 // 4d85e4 | sub ecx, dword ptr [ebp + 0x30] // 7514 | cmp dword ptr [ebp + 0xb4], esi // 4d8b1b | je 0x458 // 4c899c24a0000000 | mov edx, dword ptr [ebp + 0xb0] // 4d85db | dec esp // 0f8539feffff | mov eax, ebx // 4c8bbc2498000000 | dec ecx $sequence_3 = { 498b5320 41bbffff0000 4863423c 8bb41088000000 448b541620 } // n = 5, score = 100 // 498b5320 | or dword ptr [ebx + 8], 0xffffffff // 41bbffff0000 | xor edx, edx // 4863423c | inc ebp // 8bb41088000000 | xor eax, eax // 448b541620 | lea ecx, [edx + 6] $sequence_4 = { 4533ff eb26 4403ff 4183ff05 } // n = 4, score = 100 // 4533ff | inc esp // eb26 | mov dl, dl // 4403ff | inc edx // 4183ff05 | xor dl, byte ptr [eax + edi] $sequence_5 = { e8???????? 85ff 753a 8d4501 } // n = 4, score = 100 // e8???????? | // 85ff | dec esp // 753a | mov esp, eax // 8d4501 | dec ebp $sequence_6 = { 440f4fe8 48035d48 418bd5 488d4b30 e8???????? 418bd5 8945e0 } // n = 7, score = 100 // 440f4fe8 | add eax, edx // 48035d48 | dec eax // 418bd5 | add ecx, edi // 488d4b30 | jmp 0xd60 // e8???????? | // 418bd5 | mov dl, byte ptr [ecx] // 8945e0 | test dl, dl $sequence_7 = { 49390f 7589 41be01000000 8b430c 4803c7 } // n = 5, score = 100 // 49390f | jmp 0x355 // 7589 | dec eax // 41be01000000 | add ecx, 8 // 8b430c | dec eax // 4803c7 | mov eax, dword ptr [ebx] $sequence_8 = { c744243830387800 ff15???????? 4c8d442440 33d2 } // n = 4, score = 100 // c744243830387800 | mov edi, 3 // ff15???????? | // 4c8d442440 | dec ecx // 33d2 | mov ebx, edi $sequence_9 = { 41b800300000 4889442424 488d05f1feffff 488944242c } // n = 4, score = 100 // 41b800300000 | inc ecx // 4889442424 | xor al, byte ptr [ecx] // 488d05f1feffff | inc ebx // 488944242c | mov byte ptr [edx + ecx + 1], al condition: 7 of them and filesize < 41984 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY