SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dnespy (Back to overview)

DneSpy

VTCollection    

DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.

References
2020-10-28 ⋅ Trend Micro ⋅ Aliakbar Zahravi, Cedric Pernet, Daniel Lunghi, Elliot Cao, Jaromír Hořejší, John Zhang, Joseph C Chen, William Gamazo Sanchez
Operation Earth Kitsune: A Dance of Two New Backdoors
AgfSpy DneSpy SLUB Earth Kitsune
Yara Rules
[TLP:WHITE] win_dnespy_auto (20260917 | Detects win.dnespy.)
rule win_dnespy_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dnespy."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dnespy"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8d4508 0f434508 50 8d85f0feffff 6804010000 50 ff15???????? }
            // n = 7, score = 200
            //   8d4508               | lea                 eax, [ebp + 8]
            //   0f434508             | cmovae              eax, dword ptr [ebp + 8]
            //   50                   | push                eax
            //   8d85f0feffff         | lea                 eax, [ebp - 0x110]
            //   6804010000           | push                0x104
            //   50                   | push                eax
            //   ff15????????         |                     

        $sequence_1 = { 8bc1 c1e806 33c8 3bd3 75e8 8d0cc9 8bc1 }
            // n = 7, score = 200
            //   8bc1                 | mov                 eax, ecx
            //   c1e806               | shr                 eax, 6
            //   33c8                 | xor                 ecx, eax
            //   3bd3                 | cmp                 edx, ebx
            //   75e8                 | jne                 0xffffffea
            //   8d0cc9               | lea                 ecx, [ecx + ecx*8]
            //   8bc1                 | mov                 eax, ecx

        $sequence_2 = { c74644c0184500 e9???????? c7464410194500 e9???????? c7464458194500 e9???????? }
            // n = 6, score = 200
            //   c74644c0184500       | mov                 dword ptr [esi + 0x44], 0x4518c0
            //   e9????????           |                     
            //   c7464410194500       | mov                 dword ptr [esi + 0x44], 0x451910
            //   e9????????           |                     
            //   c7464458194500       | mov                 dword ptr [esi + 0x44], 0x451958
            //   e9????????           |                     

        $sequence_3 = { e8???????? 83c408 33c0 e9???????? ff15???????? 83c404 57 }
            // n = 7, score = 200
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   33c0                 | xor                 eax, eax
            //   e9????????           |                     
            //   ff15????????         |                     
            //   83c404               | add                 esp, 4
            //   57                   | push                edi

        $sequence_4 = { 344e 8885a8fbffff 8b85a4fbffff fec0 346f 8885a9fbffff 8b85a4fbffff }
            // n = 7, score = 200
            //   344e                 | xor                 al, 0x4e
            //   8885a8fbffff         | mov                 byte ptr [ebp - 0x458], al
            //   8b85a4fbffff         | mov                 eax, dword ptr [ebp - 0x45c]
            //   fec0                 | inc                 al
            //   346f                 | xor                 al, 0x6f
            //   8885a9fbffff         | mov                 byte ptr [ebp - 0x457], al
            //   8b85a4fbffff         | mov                 eax, dword ptr [ebp - 0x45c]

        $sequence_5 = { 83e01f 8bc8 83f801 894dd0 8d48ff }
            // n = 5, score = 200
            //   83e01f               | and                 eax, 0x1f
            //   8bc8                 | mov                 ecx, eax
            //   83f801               | cmp                 eax, 1
            //   894dd0               | mov                 dword ptr [ebp - 0x30], ecx
            //   8d48ff               | lea                 ecx, [eax - 1]

        $sequence_6 = { 8b4020 ffd0 c645fc1c 8b8dfcfaffff 888568fbffff 85c9 7413 }
            // n = 7, score = 200
            //   8b4020               | mov                 eax, dword ptr [eax + 0x20]
            //   ffd0                 | call                eax
            //   c645fc1c             | mov                 byte ptr [ebp - 4], 0x1c
            //   8b8dfcfaffff         | mov                 ecx, dword ptr [ebp - 0x504]
            //   888568fbffff         | mov                 byte ptr [ebp - 0x498], al
            //   85c9                 | test                ecx, ecx
            //   7413                 | je                  0x15

        $sequence_7 = { e8???????? 83c40c 8d85d0dfffff 83bde4dfffff08 0f4385d0dfffff 50 8d85e8dfffff }
            // n = 7, score = 200
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   8d85d0dfffff         | lea                 eax, [ebp - 0x2030]
            //   83bde4dfffff08       | cmp                 dword ptr [ebp - 0x201c], 8
            //   0f4385d0dfffff       | cmovae              eax, dword ptr [ebp - 0x2030]
            //   50                   | push                eax
            //   8d85e8dfffff         | lea                 eax, [ebp - 0x2018]

        $sequence_8 = { c70100000000 c7410400000000 85d2 7411 8b3a 85ff 7404 }
            // n = 7, score = 200
            //   c70100000000         | mov                 dword ptr [ecx], 0
            //   c7410400000000       | mov                 dword ptr [ecx + 4], 0
            //   85d2                 | test                edx, edx
            //   7411                 | je                  0x13
            //   8b3a                 | mov                 edi, dword ptr [edx]
            //   85ff                 | test                edi, edi
            //   7404                 | je                  6

        $sequence_9 = { c1e808 884c2415 0facc108 c1e808 884c2416 0facc108 8d442410 }
            // n = 7, score = 200
            //   c1e808               | shr                 eax, 8
            //   884c2415             | mov                 byte ptr [esp + 0x15], cl
            //   0facc108             | shrd                ecx, eax, 8
            //   c1e808               | shr                 eax, 8
            //   884c2416             | mov                 byte ptr [esp + 0x16], cl
            //   0facc108             | shrd                ecx, eax, 8
            //   8d442410             | lea                 eax, [esp + 0x10]

    condition:
        7 of them and filesize < 794624
}
Download all Yara Rules