Actor(s): Earth Lusca
There is no description at this point.
rule win_dizzyvoid_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.dizzyvoid." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dizzyvoid" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 48890b 48894b08 488b03 488d0c07 48894b10 } // n = 5, score = 400 // 48890b | mov dword ptr [ecx + 8], eax // 48894b08 | dec eax // 488b03 | mov dword ptr [ecx + 0x10], eax // 488d0c07 | dec eax // 48894b10 | test edi, edi $sequence_1 = { 48891d???????? 66891d???????? 48c705????????0f000000 48891d???????? } // n = 4, score = 400 // 48891d???????? | // 66891d???????? | // 48c705????????0f000000 | // 48891d???????? | $sequence_2 = { 33d2 8d4a02 ff9738010000 488bf0 } // n = 4, score = 400 // 33d2 | sar edi, 5 // 8d4a02 | dec eax // ff9738010000 | mov dword ptr [ecx], eax // 488bf0 | dec eax $sequence_3 = { 0f118980000000 48898190000000 488d0557e5ffff 498b0b 4889442450 } // n = 5, score = 400 // 0f118980000000 | movups xmmword ptr [ecx + 0x80], xmm1 // 48898190000000 | dec eax // 488d0557e5ffff | mov dword ptr [ecx + 0x90], eax // 498b0b | dec eax // 4889442450 | lea eax, [0xffffe557] $sequence_4 = { 33c0 33c9 0fa2 33c9 } // n = 4, score = 400 // 33c0 | xor eax, eax // 33c9 | xor ecx, ecx // 0fa2 | cpuid // 33c9 | xor ecx, ecx $sequence_5 = { 41b8de16ddbc 488b15???????? e8???????? 48894318 } // n = 4, score = 400 // 41b8de16ddbc | dec eax // 488b15???????? | // e8???????? | // 48894318 | mov dword ptr [ebx + 8], ecx $sequence_6 = { 4433c8 03c0 4433d0 418bc1 c1e81d 468d1cc8 } // n = 6, score = 400 // 4433c8 | mov dword ptr [ebx], ecx // 03c0 | dec eax // 4433d0 | mov dword ptr [ebx + 8], ecx // 418bc1 | dec eax // c1e81d | mov eax, dword ptr [ebx] // 468d1cc8 | dec eax $sequence_7 = { 482b3a 48c1ff05 488901 48894108 48894110 4885ff 747b } // n = 7, score = 400 // 482b3a | dec ecx // 48c1ff05 | mov ecx, dword ptr [ebx] // 488901 | dec eax // 48894108 | mov dword ptr [esp + 0x50], eax // 48894110 | dec eax // 4885ff | sub edi, dword ptr [edx] // 747b | dec eax $sequence_8 = { 5b 8b4dfc 33cd e8???????? 81c434040000 } // n = 5, score = 200 // 5b | lea eax, [ebx + 1] // 8b4dfc | dec eax // 33cd | imul ecx, eax, 0xb8 // e8???????? | // 81c434040000 | inc ecx $sequence_9 = { 57 8dbdccfbffff b90d010000 b8cccccccc f3ab a1???????? } // n = 6, score = 200 // 57 | inc ecx // 8dbdccfbffff | mov eax, 0xbcdd16de // b90d010000 | dec eax // b8cccccccc | mov dword ptr [ebx + 0x18], eax // f3ab | inc ecx // a1???????? | $sequence_10 = { 7320 8b859cfcffff 0fb68c05a8fcffff 83f104 8b959cfcffff 888c15a8fcffff } // n = 6, score = 200 // 7320 | inc ecx // 8b859cfcffff | mov eax, 0xd5b6c63f // 0fb68c05a8fcffff | inc esp // 83f104 | xor ecx, eax // 8b959cfcffff | add eax, eax // 888c15a8fcffff | inc esp $sequence_11 = { f3ab a1???????? 33c5 8945fc b9d3000000 } // n = 5, score = 200 // f3ab | xor edx, eax // a1???????? | // 33c5 | inc ecx // 8945fc | mov eax, ecx // b9d3000000 | shr eax, 0x1d $sequence_12 = { 50 8b8d90fcffff 51 e8???????? 83c40c 8bf4 ff9590fcffff } // n = 7, score = 200 // 50 | mov eax, 0xbcdd16de // 8b8d90fcffff | dec eax // 51 | mov dword ptr [ebx + 0x18], eax // e8???????? | // 83c40c | inc ecx // 8bf4 | mov eax, 0xd5b6c63f // ff9590fcffff | inc ecx $sequence_13 = { 83c40c 8bf4 ff9590fcffff 3bf4 e8???????? 33c0 } // n = 6, score = 200 // 83c40c | inc esi // 8bf4 | lea ebx, [eax + ecx*8] // ff9590fcffff | inc ecx // 3bf4 | mov eax, edx // e8???????? | // 33c0 | dec eax $sequence_14 = { e8???????? 81c434040000 3bec e8???????? 8be5 } // n = 5, score = 200 // e8???????? | // 81c434040000 | mov eax, 0xbcdd16de // 3bec | dec eax // e8???????? | // 8be5 | mov dword ptr [ebx + 0x18], eax $sequence_15 = { 81ec34040000 53 56 57 8dbdccfbffff b90d010000 } // n = 6, score = 200 // 81ec34040000 | xor edx, eax // 53 | inc ecx // 56 | mov eax, ecx // 57 | shr eax, 0x1d // 8dbdccfbffff | inc esi // b90d010000 | lea ebx, [eax + ecx*8] $sequence_16 = { c745f4b8af4000 e8???????? cc 3b0d???????? } // n = 4, score = 100 // c745f4b8af4000 | dec eax // e8???????? | // cc | mov dword ptr [ecx], eax // 3b0d???????? | $sequence_17 = { 5d c3 8b04c53cb04000 5d } // n = 4, score = 100 // 5d | dec eax // c3 | lea ecx, [edi + eax] // 8b04c53cb04000 | dec eax // 5d | mov dword ptr [ebx + 0x10], ecx $sequence_18 = { 1f 40 005c1f40 0023 d18a0688078a } // n = 5, score = 100 // 1f | dec eax // 40 | mov dword ptr [ebx], ecx // 005c1f40 | dec eax // 0023 | mov dword ptr [ebx + 8], ecx // d18a0688078a | dec eax $sequence_19 = { 83e61f c1e606 033485601c4100 8975dc 8b02 8906 8b45d8 } // n = 7, score = 100 // 83e61f | dec eax // c1e606 | mov dword ptr [ecx + 8], eax // 033485601c4100 | dec eax // 8975dc | mov dword ptr [ecx + 0x10], eax // 8b02 | dec eax // 8906 | test edi, edi // 8b45d8 | je 0x8b $sequence_20 = { 5d c3 8b04c5d4f04000 5d c3 ff15???????? 33c9 } // n = 7, score = 100 // 5d | dec eax // c3 | mov dword ptr [ebx], ecx // 8b04c5d4f04000 | dec eax // 5d | mov dword ptr [ebx + 8], ecx // c3 | dec eax // ff15???????? | // 33c9 | mov eax, dword ptr [ebx] $sequence_21 = { 8b04bd601c4100 830c06ff 33c0 eb16 e8???????? } // n = 5, score = 100 // 8b04bd601c4100 | mov eax, dword ptr [ebx] // 830c06ff | dec eax // 33c0 | lea ecx, [edi + eax] // eb16 | dec eax // e8???????? | $sequence_22 = { c1e706 8b049d601c4100 0fbe443804 83e001 } // n = 4, score = 100 // c1e706 | dec eax // 8b049d601c4100 | sub edi, dword ptr [edx] // 0fbe443804 | dec eax // 83e001 | sar edi, 5 $sequence_23 = { 59 8b7d08 833cfd40f2400000 755b 6a18 } // n = 5, score = 100 // 59 | xor edx, edx // 8b7d08 | lea ecx, [edx + 2] // 833cfd40f2400000 | call dword ptr [edi + 0x138] // 755b | dec eax // 6a18 | mov esi, eax condition: 7 of them and filesize < 479232 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY